October 10, 2026
How Cylance Lost the AI Antivirus War
Disclaimer: This article is not intended to shame, attack, or disparage any company, founder, executive, employee, investor, customer…

By David SEHYEON Baek
37 min read
- 1 The Foundstone Alumni Who Tried to Retire Signatures
- 2 What Cylance Built and What It Deliberately Did Not Build
- 3 The "Math, Not Malware" Pitch and the Credibility Tax It Created
- 4 How CrowdStrike's Modular Platform Compounded While Cylance's Product Stalled
- 5 Why the BlackBerry Deal Closed and Why It Should Not Have Closed
Disclaimer: This article is not intended to shame, attack, or disparage any company, founder, executive, employee, investor, customer, partner, or individual mentioned. It is written as a business case study for founders, executives, investors, operators, and decision-makers who may be navigating market pressure, funding constraints, strategic uncertainty, product challenges, leadership transitions, or organizational change. The purpose is to examine publicly available information, business decisions, market dynamics, and strategic outcomes in order to draw practical lessons. Any criticism is directed at decisions, strategies, execution patterns, and market positioning rather than at individuals personally. The goal is to help other businesses make better decisions, strengthen operating discipline, avoid similar risks, and build more durable companies.
Cylance arguably invented the modern category of machine-learning endpem protection, and then surrendered it. Founded in 2012 by two McAfee veterans who believed mathematics could replace signatures, the company hit roughly $171 million in trailing twelve-month revenue by January 2019, sold to BlackBerry for $1.4 billion the same month, and watched its remnants resell to Arctic Wolf six years later for $160 million in cash plus a sliver of private equity. In that same window, CrowdStrike grew from $250 million in annual revenue to nearly $4 billion, and SentinelOne went from a $46 million pre-revenue startup to a public company crossing $920 million in annual recurring revenue. The verdict from the market is not ambiguous. Cylance was first to the AI antivirus pitch, and last to the modern endpoint platform.
That gap between technical priority and durable market position is the story this article unpacks. The narrower lesson is about endpoint security. The broader lesson, for any executive selling a software platform, is about what happens when a company mistakes a wedge feature for a moat, sells too early to the wrong acquirer, and lets a polarizing marketing posture become a credibility tax it can never repay. Cylance's founders solved a real problem. Their successors built better businesses around it.
The Foundstone Alumni Who Tried to Retire Signatures
Cylance was incorporated in Irvine, California in 2012 by Stuart McClure and Ryan Permeh, both senior technical leaders departing McAfee. McClure's pedigree, according to his bios on stuartmcclure.ai and McGraw-Hill author pages, ran deep. He had co-founded Foundstone, the vulnerability management company that McAfee bought in October 2004 for $86 million, and stayed inside McAfee through the Intel acquisition in 2010, ultimately holding the title of Executive Vice President, Worldwide Chief Technology Officer, and General Manager covering nearly $3 billion of consumer and corporate security business. He was also the lead author of "Hacking Exposed," the textbook of practical offensive security first published by Osborne/McGraw-Hill in 1999 with co-authors Joel Scambray and George Kurtz. The book series ran through seven editions and sold approximately one million copies, an unusual platform for a future founder.
That last detail matters because Kurtz, McClure's "Hacking Exposed" co-author and fellow Foundstone alumnus, had left McAfee in November 2011 to found CrowdStrike with Dmitri Alperovitch and Gregg Marston. The two McAfee CTOs, Kurtz and the man who replaced him in the global CTO role, McClure, would build the two companies that defined the next generation of endpoint protection. They started within months of each other, raised from overlapping investor networks, and would diverge fundamentally on one question. Where did the intelligence live, on the endpoint or in the cloud?
Ryan Permeh, the second founder, was less famous publicly but arguably more important to the technical thesis. According to bios published by SYN Ventures, Halcyon, and BlackBerry's own engineering blog, Permeh had been Chief Scientist at McAfee, working in the Office of the CTO, and before that a Distinguished Engineer at eEye Digital Security. He had been the primary analyst on the Code Red worm in 2001 and held five security patents at the point of founding Cylance. Permeh, by every account in subsequent press, was the architect of the mathematical model that would become CylancePROTECT.
The thesis the two men sold to investors in late 2012 and early 2013 was straightforward. The signature-based antivirus model on which McAfee, Symantec, Trend Micro, and Sophos had built billion-dollar businesses was structurally broken. Signatures were reactive. Attackers had first-mover advantage every time. By the time a signature reached a customer endpoint, the attacker had already breached someone else and moved on. McClure, talking later to DFJ Growth's blog and to CXOTalk, described his McAfee years as having been spent flying to victim companies and apologizing, he privately called himself "chief apology officer." Cylance's founding language called the alternative "presponse," a predictive pre-execution posture combining attacker intuition with algorithmic models. It would, the pitch went, be the first antivirus that did not require the vendor to have seen the malware before.
Khosla Ventures and Fairhaven Capital co-led the Series A of $15 million on February 13, 2013, as TechCrunch reported at the time. Blackstone led a $20 million Series B in February 2014. DFJ Growth led a $42 million Series C in July 2015, bringing total funding to $77 million, and the round added KKR, Dell Ventures, Capital One Ventures, TenEleven Ventures, Thomvest, and DraperNexus as participants. In September 2015, In-Q-Tel, the CIA-backed investment vehicle, took an undisclosed strategic position, an important signal of credibility with federal and intelligence community buyers. Blackstone Tactical Opportunities and Insight Venture Partners co-led a $100 million Series D in June 2016 at what TechCrunch's reporting identified as the company's first billion-dollar valuation. Blackstone Tactical Opportunities led another $120 million in Series E money in June 2018. Total priced equity raised reached $297 million, with BlackBerry's later SEC Form 51–102F4 disclosing that the eventual $1.4 billion purchase included roughly $125 million paid to Cylance's debt holders, implying meaningful venture debt on top.
The revenue ramp was real. Cylance disclosed at the Series E round in June 2018 that fiscal 2018 revenue exceeded $130 million and had grown more than 90 percent year-over-year, with more than 4,000 enterprise customers including more than 20 percent of the Fortune 500. BlackBerry's pro forma disclosures filed with the SEC in April 2019 showed Cylance revenue of $171 million for the twelve months ending January 31, 2019, before a $48 million deferred-revenue write-down required by purchase accounting. Headcount peaked at roughly 900 employees, according to PitchBook records. Named customers from Inc. Magazine and Forbes profiles included Toyota, Gap, Panasonic, WWE, and Dell, the last of which embedded Cylance's technology into its Endpoint Security Suite Enterprise in November 2015, a deal that displaced McAfee on Dell business PCs and was itself a meaningful piece of the Cylance distribution flywheel.
By every visible metric in 2018, Cylance looked like the next CrowdStrike. The company's defenders inside the venture community were not wrong about the trajectory. They were wrong about how the trajectory would translate into a durable, defensible market position when the product category itself shifted under their feet.
What Cylance Built and What It Deliberately Did Not Build
CylancePROTECT, launched February 18, 2014 according to the Dark Reading and Cylance press releases at the time, was the productization of Permeh's mathematical work. The architecture, described in Cylance's "Math vs. Malware" whitepaper and in technical sessions reported by Sramana Mitra and the InfoSec Institute, can be summarized in four steps. First, the company collected tens of millions of files, executables, DLLs, PDFs, Office documents, Java archives, comprising both known-bad and known-good corpora. Second, it disassembled each file and extracted what the company called "atomic characteristics," eventually citing more than seven million features per file in marketing materials sent through Hitachi Solutions for the Japanese launch in April 2016. Examples included entropy measurements, section permissions, embedded strings, imported APIs, compiler signatures, and section sizes. Third, statistical classifiers were trained in Cylance's lab against this corpus to produce a model that could score new files on a continuous risk axis. Fourth, that trained model was compressed to roughly a 40-megabyte artifact and shipped to the endpoint, where it scored files mathematically before execution.
The architectural choice that mattered most was the fourth step. CylancePROTECT ran on the endpoint without a cloud round-trip. Files were scored locally. The agent did not need an internet connection to make a verdict. There were no daily signature updates pulled down from a vendor data center. According to Cylance's own marketing collateral, an agent could be installed and reach full protection state in seconds. This made the product genuinely useful in environments where cloud connectivity was impossible or undesirable, including air-gapped industrial networks, classified government environments, factory floors, retail point-of-sale terminals, and shipboard or oilfield deployments.
This was the technical hill on which Cylance chose to die. It was an early advantage in 2014 and 2015. It would become a strategic ceiling by 2018.
CylanceOPTICS, the company's endpoint detection and response product, was not generally available until late May 2017, as reported by CRN Australia, eWeek, and MSSP Alert at the launch. OPTICS shared a single agent with PROTECT, encrypted data locally on each endpoint rather than streaming it to a vendor cloud, and shipped with 117 pre-built detection rules. Cylance's then-Chief Product Officer Rahul Kashyap, in his eWeek interview, framed the local-storage model as a privacy and bandwidth advantage. In practice, it deprived Cylance of the global telemetry graph that CrowdStrike was already monetizing, the property of being able to see a novel threat at one customer in Singapore and protect every other customer in milliseconds.
Compare the architecture of CrowdStrike's Falcon, which had been generally available since 2013 and which CrowdStrike's S-1 prospectus describes as having been cloud-native from day one. The Falcon sensor was deliberately lightweight on the endpoint. It streamed telemetry continuously to a multi-tenant graph database CrowdStrike named the Threat Graph. The Threat Graph correlated trillions of events per day across the entire customer base. Detection logic, indicators of attack, threat intelligence, and managed threat hunting all lived in the cloud. That meant CrowdStrike could ship a new detection across its global fleet in minutes, not the days or weeks Cylance needed to retrain and redistribute its model. It meant that George Kurtz's company had network effects in the literal economic sense, every additional customer made every other customer's protection materially better.
SentinelOne, founded in January 2013 by Tomer Weingarten, Almog Cohen, and Ehud Shamir, made a third architectural bet. According to SentinelOne's S-1 filed in June 2021, the company built a single autonomous agent that could perform both pre-execution static AI scoring and runtime behavioral analysis on the endpoint itself, with cloud-side management and a cloud data lake added on top. ActiveEDR, which SentinelOne announced in February 2019, used a proprietary technology the company first called TrueContext and later rebranded as Storyline. Storyline assigned each related cluster of running processes a unique identifier and built an attack narrative in machine memory on the endpoint, eliminating the manual correlation work that legacy EDR forced analysts to perform. Storyline Active Response, announced in August 2021, added a cloud-based custom detection engine on top. SentinelOne also offered one-click ransomware rollback using Windows Volume Shadow Copy Service. The architectural net result was a product that could operate offline like Cylance, behaviorally like CrowdStrike, and autonomously remediate damage in a way neither competitor could initially match.
Three architectures, three different bets. Cylance bet that pre-execution model accuracy was the durable axis of competition. CrowdStrike bet that cloud-scale telemetry and global correlation were. SentinelOne bet on autonomous on-device behavioral AI with rollback. Over the subsequent decade, the market awarded CrowdStrike's bet most generously, awarded SentinelOne's second, and effectively punished Cylance's. The reason is not subtle. Pre-execution model accuracy is a feature. Cloud-scale telemetry, modular platform expansion, and autonomous response are products that grow into platforms. Cylance built a feature and called it a category.
The technical case that this assessment is too harsh runs as follows. In 2014 and 2015, Cylance's prevention rates on never-before-seen malware genuinely embarrassed signature-based incumbents. The company's commissioned SE Labs "Predictive Advantage" report published in April 2018 claimed CylancePROTECT's May 2015 model could still detect malware released up to 33 months later, the source of the company's "years before it existed" marketing claim. Some of that test methodology was self-serving, the AI model used in the test was supplied by Cylance, but the underlying performance was real enough that incumbents like Symantec felt threatened enough to commission their own counter-tests. Cylance's technology, on its narrow axis, worked.
The technical case for the harsh assessment is that the narrow axis was the wrong one to optimize against. As behavioral malware, fileless attacks, living-off-the-land techniques using legitimate Windows binaries, and identity-based attacks via stolen credentials became the dominant attacker tactics through 2018 and 2019, pre-execution file scoring became less and less useful relative to runtime behavioral monitoring and cloud-scale correlation. Cylance's central architectural choice optimized for a threat model that was already aging when the company shipped its first product. The competitors had read the same threat data and made better bets.
The "Math, Not Malware" Pitch and the Credibility Tax It Created
For approximately three years between 2014 and 2017, Cylance ran one of the most aggressive marketing operations in enterprise security. The campaign had a slogan, "Math vs. Malware", and a touring road show called the Unbelievable Tour, launched March 3, 2015 in Tampa and ending May 7, 2015 in Dallas after stops in more than 20 cities, according to the Marketwired press release. Cylance ran live malware bake-offs in customer conference rooms, downloading samples from VirusTotal in real time and pitting CylancePROTECT against Symantec, McAfee, Trend Micro, and Sophos installations on parallel laptops. Cylance disclosed the cumulative results, 99 percent block rate on roughly 2,200 samples, versus approximately 50 percent for Symantec and McAfee and 33 percent for Trend Micro. The events were theater. They were also extremely effective at moving the conversation away from the trade press's preferred bake-offs and toward Cylance's own controlled environment.
The CMO at the time, Greg Fitzgerald, told ChannelBiz in March 2016 that the demos were the single most productive lead-generation mechanism the company had. Combined with the November 2015 Dell OEM deal, described in Dark Reading at the time as making Cylance "the only tier one PC vendor" partner among modern AV providers, the company's go-to-market story was, briefly, the most exciting one in endpoint security. Customers liked the price disruption too. Cylance priced aggressively under legacy AV on a per-seat basis, leveraging the channel and resellers like SHI to displace incumbents at the renewal cycle.
The credibility tax began to compound around the same time. In November 2016, a systems engineer evaluating Cylance discovered that seven of forty-eight "malware" samples Cylance had supplied from a Box-hosted folder for prospect testing were not, in fact, functional malware. Dan Goodin and Sean Gallagher at Ars Technica published "The mystery of the malware that wasn't" in April 2017, documenting the discrepancy. Cylance's Vice President Chad Skipper acknowledged that the company had packed real malware with the MPRESS and VMProtect packers, which sometimes broke functionality but, in his framing, preserved the "earmarks" of malicious behavior. Critics within the industry, including Mike Viscuso at Carbon Black, accused Cylance of stacking the deck so that only CylancePROTECT could detect samples its own model had been trained on. Independent testing by MRG Effitas, also in April 2017, found that CylancePROTECT was uniquely sensitive to VMProtect-packed files in a way that effectively guaranteed Cylance would win any test using packed samples, exactly the methodology Cylance recommended on its testmyav.com site.
At the same time, Cylance was attacking the testing labs themselves. In late 2016 and early 2017, after a Symantec-commissioned MRG Effitas and AV-Comparatives joint test produced unfavorable results, Cylance published a series of blog posts accusing both labs of "fraud, bias, software piracy, and extortion," according to CSO Online. The labs responded, with documentation from MRG Effitas confirming legal purchases of CylancePROTECT from authorized reseller Malware Managed and showing that Cylance had revoked their license on January 7, 2017, the standard playbook of a vendor uncomfortable with how it was being tested. The June 2017 MRG-Effitas EternalBlue/DoublePulsar test, conducted in the immediate aftermath of WannaCry, found CylancePROTECT failed to detect the DoublePulsar backdoor and the underlying SMB exploit, blocking only the eventual file payload. SentinelOne passed.
Then came July 2019. Skylight Cyber researchers Adi Ashkenazy and Shahar Zini in Sydney, Australia, published a paper titled "Cylance, I Kill You!" The methodology was elegant and devastating. The researchers reverse-engineered the CylancePROTECT scoring model, which produced verdicts on a -1000 to +1000 scale, and discovered that the model was unusually sensitive to strings present in a small set of whitelisted executables. By appending approximately 60 kilobytes of strings extracted from a specific online video game, initially anonymous, later revealed at a BSides Sydney presentation in September 2019 to be Rocket League, they could shift the score of Mimikatz from -852 (clearly malicious) to +999 (clearly benign). The bypass worked against 100 percent of the Center for Internet Security's top-10 May 2019 malware list and approximately 90 percent of a broader 384-sample test set that included WannaCry, SamSam, Mimikatz, and Meterpreter. Vice's Kim Zetter broke the story; Dark Reading, BankInfoSecurity, SC Media, and TechTarget followed.
Skylight did not give Cylance prior notice, citing Australian CERT's 45-day disclosure policy and arguing that universal adversarial bypasses of ML models did not constitute a vulnerability in the traditional sense. Cylance's response, published July 21, 2019 by then-Chief Scientist Ryan Permeh, characterized the issue as not a "universal bypass" but a "manipulation of a specific type of feature… in limited circumstances," and described three remediations including anti-tampering controls and model retraining. The damage was already done. Virus Bulletin editor Martijn Grooten captured the prevailing industry sentiment with the line that defined the moment, telling reporters that Cylance's "crime is not that they coded AI poorly. Their crime is calling what they did AI."
That sentence is the cleanest articulation of Cylance's strategic problem. The company had spent five years positioning itself as a categorical leap forward in security, with marketing claims that bypassed the normal qualifications applied to machine-learning systems. When researchers demonstrated that the model could be defeated by string-padding tricks of the kind that any working data scientist would predict, the company's "trust the math" tagline became indefensible. A vendor that had cultivated a near-religious posture about its own technical superiority discovered the cost of having converted skeptics into enemies.
It is worth being precise about what this episode did and did not prove. It did not prove that machine learning is useless for malware detection, every modern vendor, including CrowdStrike and SentinelOne and Microsoft, uses ML extensively. It did prove that an ML model deployed without telemetry diversity, without ensembling against adversarial inputs, and without continuous retraining against an active attacker is brittle in ways that classical detection is not. It also proved that customers who had been told for years that "the math" was unimpeachable now had to ask their procurement teams whether they had been sold a story rather than a product. By July 2019, Cylance was already inside BlackBerry. The reputational repair was someone else's problem, and that someone else did not have the appetite or the bench to do it.
How CrowdStrike's Modular Platform Compounded While Cylance's Product Stalled
Beneath the marketing controversies, the more fundamental Cylance failure was a product roadmap that did not extend from endpoint protection to a multi-product platform fast enough. CrowdStrike provides the cleanest counter-example. By the time CylancePROTECT was generally available in early 2014, CrowdStrike had already shipped Falcon Insight, its EDR product, and Falcon OverWatch, its managed threat hunting service, was in market within roughly a year. CrowdStrike's S-1 filed in May 2019 disclosed ten distinct Falcon modules: Prevent, Insight, OverWatch, Discover, Intelligence, Spotlight, Device Control, Firewall Management, Intelligence Premium, and Falcon for Mobile. Customers could buy any combination. Each module ran on the same agent and the same Threat Graph, which meant CrowdStrike's incremental cost to ship a new module against a new buyer persona was extraordinarily low.
CrowdStrike's acquisitions then layered new modules on top of that single-agent foundation. Preempt Security, acquired in September 2020 for roughly $96 million, became Falcon Identity Threat Protection, opening the identity buyer persona. Humio, acquired in March 2021 for approximately $400 million, became Falcon LogScale and then Falcon Next-Gen SIEM, opening the security operations buyer. Adaptive Shield, acquired in November 2024 for approximately $300 million, became Falcon Shield for SaaS security posture management. Flow Security, acquired in 2024 for approximately $200 million, extended cloud data security. Each acquisition was a module added to the same architecture. Charlotte AI, launched in 2023, added a generative AI SOC assistant across the stack. Falcon Complete, the company's managed detection and response offering, became one of the most profitable MDR businesses in security according to consistent Gartner analyst commentary.
The financial result of this modular compounding was visible in CrowdStrike's revenue, which grew from $249.8 million in fiscal year 2019 to $3.95 billion in fiscal year 2025, according to the company's 10-K filings. ARR reached $4.24 billion as of January 31, 2025. IDC's Worldwide Modern Endpoint Security Market Share report for the trailing twelve months ending June 2022 placed CrowdStrike first at 17.7 percent, up from 13.8 percent the prior year, with revenue growth of 62.4 percent year-over-year in the segment. Cylance, by the same IDC report, sat fifteenth at 1.3 percent, down from 1.5 percent.
Cylance did not produce a comparable platform. CylanceOPTICS was the only meaningful product extension during the Cylance-as-Cylance years, and even that lagged Falcon Insight by approximately two years. There was no managed hunting service at remotely the scale of OverWatch. There was no native identity product. There was no SIEM. There was no cloud workload protection at any meaningful market share. The company's R&D dollars were absorbed by maintenance of CylancePROTECT, by retraining the ML model in response to controversies like Skylight, and by the demands of integrating with BlackBerry after February 2019. The product debt accumulated faster than the engineering organization could service it.
SentinelOne ran the same playbook as CrowdStrike on a delay, but with credible execution. The company acquired Scalyr in February 2021 for approximately $155 million, giving it the cloud data lake foundation for XDR. It acquired Attivo Networks in March 2022 for $616.5 million, opening the identity threat detection space against CrowdStrike's Preempt. It acquired PingSafe in January 2024 for more than $100 million to enter cloud-native application protection. Prompt Security followed in August 2025 for approximately $250 million, bringing AI runtime security into Singularity. Observo AI followed in September 2025 to add an AI-native data pipeline for SIEM. By fiscal year 2025, SentinelOne reported total revenue of $821.5 million, growth of 32 percent year-over-year, and ARR crossing $920 million per its 8-K filings. The company had been named a Leader in Gartner's Magic Quadrant for Endpoint Protection Platforms for four consecutive years through 2024, and Cylance under BlackBerry had been demoted to Niche Player.
The pattern across both winners is the same. Endpoint was the wedge. Platform was the business. Cylance, by treating endpoint as the business rather than the wedge, condemned itself to compete in a category that was being commoditized, by Microsoft Defender for Endpoint, by behavioral incumbents adding ML, by next-generation entrants, exactly when the buyers it most needed were rebudgeting toward consolidated platforms.
Why the BlackBerry Deal Closed and Why It Should Not Have Closed
By mid-2018, the executive team at Cylance had a strategic decision to make. Revenue growth was strong but the rate was slowing. The company had been positioning for an IPO, with reporting by Business Insider and TheStreet describing late-stage bake-off conversations with bankers. CrowdStrike was visibly preparing its own IPO and was widely expected to price well in the first half of 2019. SentinelOne had just raised $120 million at a $1.1 billion valuation in November 2018. Cylance's $120 million Series E from Blackstone in June 2018 had set an implied private-market mark, but the public-market arithmetic was about to get crowded.
Then BlackBerry called. The Canadian company, under CEO John Chen, had spent five years repositioning itself from a failed handset maker into an enterprise software and embedded systems vendor, anchored by its Unified Endpoint Management product and its QNX automotive operating system, which by Chen's claim ran inside more than 120 million vehicles. Chen wanted a cybersecurity centerpiece for the BlackBerry Spark platform he was building. He announced on November 16, 2018 that BlackBerry would buy Cylance for $1.4 billion in cash, the largest acquisition in BlackBerry's history. The deal closed February 21, 2019. Advisors were Perella Weinberg Partners and Morrison Foerster on the BlackBerry side and Morgan Stanley and Jones Day on the Cylance side. According to BlackBerry's SEC Form 6-K filed in April 2019, $899 million of the purchase price became goodwill on BlackBerry's balance sheet, bringing the company's total goodwill to roughly $1.4 billion.
Several things about this deal were defensible in November 2018, and most of them stopped being defensible within twelve months. The price, $1.4 billion against approximately $171 million of trailing twelve-month revenue, was roughly 8x revenue, not cheap, but not absurd by 2018 cybersecurity standards. The strategic logic of pairing endpoint AI with embedded automotive systems and IoT was not nonsensical on paper. Cylance's investor base, particularly Blackstone, was paid out at a clean and definite multiple rather than the variable outcome of an IPO that would coincide with CrowdStrike's. The executive team got liquidity.
What killed the deal economically was visible to anyone paying attention to CrowdStrike's June 2019 IPO. CrowdStrike priced at $34 per share on June 11, 2019, opened at $63.50 on June 12, and closed the first day at $58, valuing the company at approximately $11.4 billion against fiscal 2019 revenue of $249.8 million, a revenue multiple roughly five times what Cylance had received from BlackBerry four months earlier. The public market's repricing of cloud-native endpoint security was, in the same quarter Cylance was being absorbed by BlackBerry, telling the founders and bankers of every comparable company that their floor had risen by an order of magnitude. Cylance's $1.4 billion would have been a respectable opening valuation in a CrowdStrike-comparable IPO; it became, in retrospect, a fraction of the value the company could plausibly have captured by waiting eighteen months and going public.
The strategic problem was worse than the price. BlackBerry was not the natural acquirer for an endpoint security business that needed to build a cloud-native platform fast. BlackBerry's culture, under Chen, was managed-for-cash, focused on margin expansion in slow-growth enterprise software categories, and dominated by an embedded-systems and regulated-industries customer base that bought QNX and AtHoc and SecuSUITE rather than commercial endpoint AV. The company did not have the engineering depth, the SaaS operational muscle, or the public-market patience to invest behind Cylance the way CrowdStrike's public investors would invest behind Falcon. From the moment the deal closed, the most important question about Cylance was not "what is the product roadmap" but "what is BlackBerry willing to spend on R&D to keep this competitive."
The answer, as the next five years would show, was "not enough."
The Post-Acquisition Collapse
Stuart McClure stayed on as president of BlackBerry Cylance through the integration period. On September 24, 2019, John Chen announced on BlackBerry's Q2 fiscal year 2020 earnings call that McClure was leaving. According to SecurityWeek's and Orange County Business Journal's reporting that week, Chen said McClure had "made a personal decision, which we have to respect" and that he "would have wanted him to stay longer." McClure's tenure as president had lasted approximately eight months from closing. Chief Operating Officer Daniel Doimo replaced him.
McClure's departure was accompanied by what CRN, reporting picked up by SecurityWeek, described as a broader executive exodus. Names cited in those accounts included Didi Dayton, Tim Mackie, Louise Cooke, Malcolm Harkins (Chief Security and Trust Officer), Chris Scanlan, Abigail Maines, and Brian Stoner. Ryan Permeh, the co-founder and chief scientist, stayed longer than McClure, working inside BlackBerry's Office of the CTO as SVP and Chief Security Architect. His own departure date is not publicly fixed, but the BusinessWire announcement of SYN Ventures' $300 million Fund II close on May 25, 2022 named Permeh as Operating Partner at the firm, suggesting his transition out of BlackBerry occurred sometime before that announcement.
McClure's subsequent activity is instructive. He founded NumberOne AI in 2021 in Newport Beach, raising $13 million in October 2022 from investors including former RSA CEO Art Coviello, Aidan Kehoe, Alex Weiss, Ray Zadjmool, Drumwright Investments, B5 Capital, Miramar Digital Ventures, and former Compaq and WorldCom CEO Michael Capellas. He became CEO of Qwiet AI, the company formerly known as ShiftLeft, in 2022, rebranding the firm in February 2023 to focus on AI-powered application security. He founded Wethos AI, which raised a $7.5 million seed for AI-driven team-dynamics analytics, according to OCBJ's 2024 OC500 list. He took board roles at Globus AI and NetRise. McClure, in other words, did exactly what successful exited founders typically do, built a portfolio of next-cycle bets. He has been notably circumspect in public commentary about BlackBerry's management of Cylance.
Under Doimo and his successors, the Cylance product organization was reorganized into BlackBerry's broader cybersecurity business unit. The CylancePROTECT, CylanceOPTICS, and CylanceGUARD product names were retained for several years but eventually consolidated under the CylanceENDPOINT brand. BlackBerry introduced a zero-trust network access product called BlackBerry Gateway in 2021 and pushed an XDR strategy under the BlackBerry Spark banner that attempted to integrate Cylance's endpoint telemetry with UEM, AtHoc, and SecuSUITE data. None of these efforts produced meaningful market share gains. Gartner's 2021 Magic Quadrant for Endpoint Protection Platforms placed BlackBerry as a Niche Player and included an explicit "Caution" about brand dilution from the BlackBerry name, according to the publicly available copy of that report. The company remained a Niche Player through the 2024 MQ.
The financial trajectory of BlackBerry's cybersecurity segment tells the story without commentary. Fiscal year 2021 cybersecurity segment revenue, the first full BlackBerry fiscal year of Cylance ownership, was $491 million, per BlackBerry's Q1 fiscal year 2022 8-K filing. Fiscal year 2022 came in at approximately $477 million, a 3 percent decline. Fiscal year 2023 fell to roughly $418 million. Fiscal year 2024 fell further to $378 million. Cybersecurity ARR peaked at $347 million in Q4 fiscal year 2022 and bottomed at approximately $273 million in Q3 fiscal year 2024, according to the company's quarterly 8-K disclosures. Dollar-based net retention rate fell to as low as 81 percent in mid-fiscal-2024, indicating customer churn well in excess of expansion, the financial signature of a product losing share at the renewal cycle.
The impairment charges followed the revenue. BlackBerry took a $594 million non-cash goodwill impairment on the Spark/Cylance reporting unit in Q1 fiscal year 2021, attributed partly to COVID-19 conditions but mostly to revised forecasts. The company took an additional $245 million goodwill impairment plus a $231 million long-lived asset impairment, a combined $476 million non-cash charge, in Q4 fiscal year 2023. Smaller impairments of $50 million combined followed in fiscal year 2024. Cumulative impairment charges tied to the Cylance and Spark unit exceeded $1 billion before any sale was contemplated.
John Chen retired November 4, 2023, after his contract expired and was not renewed. Chairman Richard Lynch served briefly as interim CEO. On December 11, 2023, BlackBerry announced John Giamatteo as permanent CEO. Giamatteo, who had joined BlackBerry as president of the cybersecurity business unit in October 2021, had previously been president and CRO at McAfee, COO at AVG Technologies, and senior at Nortel and RealNetworks, a profile of integration and turnaround leadership rather than category creation. The same announcement disclosed that BlackBerry would scrap Chen's planned IPO of the IoT business and pursue a full separation of the IoT and cybersecurity divisions into standalone units.
Twelve months later, Giamatteo found a buyer for the endpoint piece. On December 16, 2024, BlackBerry and Arctic Wolf jointly announced that Arctic Wolf would acquire Cylance's endpoint security assets, including CylancePROTECT, CylanceOPTICS, and the CylanceMDR managed service. Per BlackBerry's 8-K filed in connection with the deal, the consideration was $160 million in cash, subject to adjustments, plus approximately 5.5 million common shares of Arctic Wolf, which was privately held and last valued at $4.3 billion in 2021. Cash was structured as approximately $80 million at closing plus approximately $40 million one year after closing. The transaction closed February 3, 2025. BlackBerry retained Unified Endpoint Management, AtHoc, and SecuSUITE, which it rebranded as Secure Communications.
The arithmetic is brutal. BlackBerry paid $1.4 billion for Cylance in cash in February 2019. It sold the endpoint assets six years later for $160 million in cash plus private equity worth, at the most optimistic implied $50-per-share valuation of Arctic Wolf, perhaps $275 million in aggregate. The company recognized cumulative goodwill and asset impairments of roughly $1.12 billion before the sale, meaning the disposal itself produced a small $10.4 million pre-tax gain on the already-written-down book value. TechCrunch summarized the outcome accurately: BlackBerry sold Cylance for "roughly 7x less than they paid for it." The Globe and Mail's David Milstead, in a sharper retrospective, called the unit "the costliest gamble during the 10-year reign of John Chen" and described it as a "money pit" projected to lose $50 million on $90 million of revenue in the final pre-sale fiscal year. Canaccord Genuity analyst Kingsley Crane appeared on BNN Bloomberg the day of the announcement to make the same arithmetic point. BlackBerry's stock rose approximately 14 percent on the announcement, the market's verdict that the company was better off without the asset.
Nick Schneider, Arctic Wolf's president and CEO, framed the acquisition cleanly in the announcement statement, saying that "endpoint solutions alone have failed to live up to the outcomes they have promised for years" and that Arctic Wolf would integrate Cylance's AI prevention capabilities into its Aurora open-XDR platform. Arctic Wolf rebranded the product line as Aurora Endpoint Security, with four offerings spanning self-managed protection, managed defense, and on-demand managed defense. The business that Cylance had built in 2014 to be the antivirus replacement was, in 2025, repurposed as the endpoint-telemetry layer for someone else's managed-detection platform.
What CrowdStrike and SentinelOne Did Right That Cylance Did Not
The straightforward summary of why CrowdStrike and SentinelOne won is that they built businesses while Cylance built a product. The longer version is more useful, because each winner won for slightly different reasons that suggest different lessons for executives in other categories.
CrowdStrike's central correct decision, made by George Kurtz and Dmitri Alperovitch in 2011, was cloud-native architecture. Kurtz has told the story repeatedly, including in his interviews around the June 2019 IPO, that the cloud bet was viewed as risky at the time, enterprise security buyers were widely skeptical about putting sensitive endpoint telemetry into a multi-tenant cloud. Kurtz bet that the architectural advantages of a global Threat Graph would overwhelm the buyer skepticism within five years. They did. By 2015 the Threat Graph was already processing tens of billions of events per day. By 2024 the figure was 6.2 trillion daily events. Every novel attack pattern detected at one customer became automatic protection at every other customer in minutes. No on-device ML model, including Cylance's, could match the breadth of that signal.
CrowdStrike's second correct decision was platform modularity. The Falcon agent was deliberately a thin sensor with the intelligence in the cloud, which meant new product modules could be shipped to existing customers without requiring new agent installations. This produced what financial analysts now call platform compounding, net retention rates regularly above 120 percent driven by customers buying additional modules at renewal. The Falcon platform reached the point where the marginal cost to CrowdStrike of selling a new module against an existing customer was effectively zero. The acquisitions of Preempt, Humio, Adaptive Shield, and Flow extended the same modular pattern into adjacent categories.
CrowdStrike's third correct decision was managed services at scale. Falcon OverWatch, the managed threat hunting service, started early, by 2014–2015 according to CrowdStrike's historical materials, and Falcon Complete, the full MDR service, followed. By 2024 these services were widely regarded as the leading managed detection and response offerings in the market, and they served a structural purpose beyond their direct revenue. They gave CrowdStrike's analysts continuous visibility into the live attack environment, which fed back into product detection logic, which improved Falcon for every customer. Cylance had a managed service called CylanceGUARD, but it never reached comparable scale or recognition.
The single most damaging CrowdStrike event in the past three years was the July 19, 2024 outage, in which a faulty Falcon sensor update crashed approximately 8.5 million Windows endpoints globally, prompting Delta Air Lines to sue for $500 to $550 million in damages. That event was described in technology press at the time as the largest IT outage in history. Notable about that event is that it did not materially damage CrowdStrike's competitive position. Customer retention held. Revenue continued to grow. Falcon Flex, a new commercial structure introduced post-outage to give customers flexibility on commitment terms, accelerated platform expansion deals. The brand survived because the underlying value of the platform, to security operations centers running on Falcon telemetry, was deep enough to absorb a singularly damaging operational event. Cylance's brand never reached that depth. The Skylight bypass in 2019 was far smaller in operational impact than the CrowdStrike outage, but it damaged Cylance's positioning far more, because Cylance had built its brand on a single technical claim rather than on a deep operational dependency.
SentinelOne's central correct decision was autonomous response. Tomer Weingarten's pitch from the founding was that human SOC analysts were the binding constraint on enterprise security, and that an agent that could autonomously detect, contextualize via Storyline, and remediate via rollback would scale where human-attended EDR could not. That positioning matched the customer pain point that grew through 2018 and 2019 with the spread of ransomware, the speed-of-response problem. SentinelOne's one-click rollback of ransomware encryption, built on Windows Volume Shadow Copy Service, became a procurement requirement at many mid-market and channel-led accounts that Cylance never won.
SentinelOne's second correct decision was channel and MSP economics. The company's S-1 disclosed that SHI International accounted for 14 percent of fiscal 2020 revenue and 13 percent of fiscal 2021 revenue. The product was architected for multi-tenant reseller deployment in a way that Cylance's enterprise-direct model was not, which meant SentinelOne won an outsized share of the managed service provider and managed security service provider segments. As MSPs and MSSPs became the dominant procurement channel for mid-market endpoint protection through 2020–2023, SentinelOne benefited disproportionately.
SentinelOne's third correct decision was disciplined acquisitions. Scalyr in February 2021 for $155 million produced the cloud data lake that enabled Singularity XDR. Attivo in March 2022 for $616.5 million produced the identity threat detection product that countered CrowdStrike's Preempt. PingSafe in January 2024 for more than $100 million entered cloud security. Prompt Security in August 2025 added AI runtime security. Each acquisition extended Singularity along the same modular pattern CrowdStrike had pioneered.
Both winners also benefited from public-market capital availability that Cylance never accessed. CrowdStrike's IPO on June 12, 2019 raised approximately $612 million at $34 per share, valuing the company at $6.7 billion at the offering price and roughly $11.4 billion on first-day close. SentinelOne's IPO on June 30, 2021 raised approximately $1.2 billion at $35 per share, the largest cybersecurity IPO in history at the time per CNBC, with first-day close valuing the company above $10 billion. Both companies used the IPO proceeds and subsequent secondary issuances to fund R&D, sales expansion, and acquisitions at a pace that BlackBerry's cash-management posture would not have funded for Cylance even had the BlackBerry deal not happened. The capital pool a public cybersecurity platform could access in 2019–2021 was an order of magnitude larger than the strategic-acquirer pool. Cylance's founders chose the smaller pool four months too early.
Finally, both winners cultivated independent analyst relations and third-party testing carefully. Both were named Leaders in Gartner's Magic Quadrant for Endpoint Protection Platforms for multiple consecutive years, CrowdStrike for five years through 2024, SentinelOne for four years through 2024. Both submitted to MITRE ATT&CK evaluations and used the results in marketing. Cylance, by contrast, attacked the labs that produced unfavorable results, withdrew its products from comparative tests it could not control, and was punished by the analyst community for it. The Cylance posture in 2016–2017 of treating MRG Effitas, AV-Comparatives, and AV-TEST as adversaries to be discredited became, by 2019, part of the case Gartner and Forrester made for not placing Cylance higher in their evaluations. The labs outlived the rhetoric.
Lessons for Cybersecurity and Technology Executives
The Cylance story produces a set of strategic principles that generalize well beyond endpoint security. Several are obvious in retrospect, which is partly the point. The patterns that defeated Cylance are recurring patterns in software M&A and platform competition, and they will defeat other companies whose executives convince themselves that "this time is different."
The first lesson is about the difference between a feature and a moat. Pre-execution ML scoring of executables was, in 2014, a genuine technical advance over signature-based detection. It was also, by 2017, replicable by every competent vendor in the category. Cylance built its entire commercial proposition on a technical capability with a half-life of approximately three years before competitive imitation. The deeper architectural choices, cloud-native telemetry graphs, multi-product agents, autonomous response, modular platforms, had ten-year half-lives or more, because they produced compounding network effects, switching costs, and operational dependencies that imitation alone could not undo. Executives evaluating a wedge feature should ask, with discipline, how long the feature lead will persist after competent competitors decide to copy it, and what they will build during that window to deepen the moat. Cylance built marketing. CrowdStrike and SentinelOne built platforms.
The second lesson is about platform extension velocity. The transition from endpoint protection to endpoint detection and response to extended detection and response to security operations was foreseeable by 2015 to anyone reading Gartner's hype cycles or talking to enterprise CISOs. Cylance shipped its EDR product, CylanceOPTICS, in May 2017, approximately two years after CrowdStrike had Falcon Insight in market and approximately the same time SentinelOne was preparing ActiveEDR. The two-year lag became permanent because Cylance's architecture, local-storage telemetry, no graph database, no global correlation, could not be retrofitted into a cloud-scale XDR posture without rebuilding the core product. Executives running a wedge product should plan the platform extensions before the wedge revenue peaks, not after. Single-product strategies in software categories with strong adjacent demand always lose to multi-product platforms over a ten-year horizon. The exception is when the product is a true bottleneck monopoly. Endpoint AV was never that.
The third lesson is about cloud-native architecture as a strategic moat. CrowdStrike's cloud bet in 2011 looked risky at the time and looks obvious in 2026. The reason it produced such a durable advantage is that the cloud-native architecture itself, once at scale, became a competitive asset that competitors could not match without a multi-year, multi-hundred-million-dollar rebuild. Cylance's local-agent architecture, which Cylance's marketing actively celebrated in 2014–2017, became its central liability in 2019–2024. Executives in other software categories should be precise about which architectural choices are temporary tactical advantages and which are durable strategic moats. The two often look identical at the point of decision and diverge dramatically over the subsequent decade.
The fourth lesson is about the strategic risks of selling to a culturally misaligned acquirer at the wrong time in the public-market cycle. BlackBerry was a managed-for-cash enterprise software business with a slow-growth product mix, a regulated-industries customer base, and no recent track record of scaling consumer or SMB SaaS. It bought a high-growth, channel-driven, marketing-heavy cybersecurity company at the peak of its private-market valuation and then could not afford to fund the platform extensions the business needed to remain competitive. CrowdStrike's IPO four months after the deal closed effectively repriced the entire category at five times what BlackBerry paid Cylance. Founders considering strategic exits should ask three questions explicitly. Does the acquirer have the cultural and operational pattern to scale this business? What is the comparable public-market price of this business in the next twelve months? And what is the cost of being locked inside a strategic acquirer's slow cash flow when the public market is repricing the category? Cylance got two of these three questions wrong.
The fifth lesson, related but distinct, is about founder retention post-acquisition. McClure departed BlackBerry eight months after the deal closed. Permeh stayed longer but eventually transitioned to SYN Ventures. The broader executive exodus, Dayton, Mackie, Cooke, Harkins, Scanlan, Maines, Stoner, among others, happened within roughly twelve months of closing. Strategic acquirers who plan to retain talent after a high-priced deal close should structure earn-outs and operating roles that align with founder ambitions, not with the acquirer's preferred reporting structure. BlackBerry did not. The institutional knowledge of how Cylance's go-to-market and product development actually worked departed with the founders, and the post-acquisition cybersecurity organization never reached the same operational tempo. Acquirers paying premium multiples for talent should treat the founders' next two to three years as part of the asset they are buying, and they should be candid about the cultural fit.
The sixth lesson is about reputational risk in technology marketing claims. The "Math vs. Malware" campaign, the Unbelievable Tour, the "trust the math" tagline, and the "years before it existed" claim from the SE Labs Predictive Advantage test all served Cylance enormously well from 2014 to 2017. They also accumulated a credibility tax that came due in 2019 when Skylight Cyber demonstrated that the model could be defeated by string-padding. The lesson is not that ML marketing is bad, every modern endpoint vendor markets ML claims. The lesson is that asymmetric marketing claims, claims that imply qualitative superiority beyond what the technology can defend against an adversarial researcher, create a brittle brand. Executives marketing AI capabilities in 2026 should observe how Cylance's "trust the math" became indefensible the moment researchers demonstrated math could be gamed, and they should price their own AI marketing claims against the cost of a similar demonstration against their product. Brand humility is cheap. Brand defensiveness, after a credibility hit, is not recoverable.
The seventh lesson is about independent test results and third-party validation. Cylance's posture toward MRG Effitas, AV-Comparatives, and AV-TEST through 2016–2017 was overtly adversarial. The company accused labs of fraud, software piracy, and extortion. It revoked license keys when labs produced unfavorable results. It published commissioned tests with methodologies it controlled. The cumulative effect was that the independent testing community, which advises analyst firms and procurement teams, treated Cylance as a problem vendor by 2018 and treated its competitors more favorably. CrowdStrike and SentinelOne, by contrast, submitted aggressively to MITRE ATT&CK evaluations, leaned into Gartner Magic Quadrant assessments, and used unfavorable results as a roadmap for improvement rather than as a public relations crisis. Executives whose products rely on third-party performance comparisons should treat the testing community as a permanent stakeholder, not a tactical adversary, even when individual test results are unflattering.
The eighth lesson is about channel and partner ecosystems. SentinelOne's channel and MSP-friendly architecture was a deliberate strategic asset, recognized in the company's S-1 disclosures about reseller concentration and reflected in its mid-market wins. CrowdStrike's Falcon Complete MDR offering became a force multiplier for channel partners by giving them a productized service to resell. Cylance, by comparison, never fully built either a strong MSP economics layer or a comparable MDR-as-a-service offering. As MSPs and MSSPs became the dominant procurement channel for mid-market endpoint protection through 2020–2023, Cylance's go-to-market increasingly looked enterprise-direct in a market that had moved on. The lesson is to architect for channel economics from the founding, especially in categories where mid-market and SMB demand will eventually exceed enterprise demand.
The ninth lesson is about category creation versus category leadership. Cylance helped create the category of AI-powered endpoint protection. It was first to market with the marketing pitch, first to commission the testing methodology that demonstrated its advantages, and first to displace signature-based incumbents in named accounts. It lost category leadership anyway. Category creation is a marketing achievement. Category leadership is a product, organizational, and capital-allocation achievement. They require different skills and different time horizons. Executives whose companies have just created a category should be careful about confusing the two. The companies that ultimately led the cloud category, the mobile category, the SaaS CRM category, and many others were rarely the companies that created them. The pattern repeats in cybersecurity.
The tenth lesson is about capital strategy. Cylance chose a $1.4 billion strategic sale in November 2018 over a public market path that, based on CrowdStrike's June 2019 IPO, would have valued the company at multiples of that price. The strategic sale produced certain liquidity. The IPO path would have produced larger valuations but also higher variance. The right answer depended on the founders' and investors' risk preferences and capital needs. The wrong answer, in retrospect, was choosing a strategic acquirer who would underinvest in the business for the next six years rather than choosing either a strategic acquirer with the operational capacity to scale the business or a public-market path that would have funded the platform extensions. Founders considering exits should be precise about which exit path actually produces the best long-term outcome for the technology and the team, not merely the best near-term liquidity outcome for early investors. Sometimes those are the same. In Cylance's case they were not.
The eleventh lesson, broader still, is about the difference between technology innovation and durable business model. Cylance's machine-learning models were a real technology innovation. CrowdStrike's cloud-native graph database was a real technology innovation. SentinelOne's Storyline autonomous response was a real technology innovation. All three companies started with comparable technical credibility. Only two of the three built durable businesses around the technology. The differentiator was not the quality of the underlying innovation but the quality of the surrounding choices, architectural extensibility, platform modularity, capital strategy, channel economics, M&A discipline, third-party relationships, and brand humility. Technology innovation is necessary and routinely insufficient. Executives evaluating technical bets in their own companies should pressure-test which of the surrounding choices are actually in place before they commit to the bet.
The twelfth and final lesson is about cybersecurity-specific dynamics that bear on broader technology strategy. The cybersecurity market is one of the few enterprise software categories where the product must defeat an active, adaptive adversary. That dynamic makes asymmetric marketing claims more dangerous than in adjacent software categories, because adversarial researchers will actively work to disprove the claims. It makes architectural choices about telemetry and global correlation more valuable, because the network effect of a global threat graph is a structural advantage against the adversary that no single-customer deployment can match. It makes platform consolidation more important, because customers ultimately want a unified view of security data, not best-of-breed point products. Executives in cybersecurity should price these dynamics aggressively into their strategic choices. Executives in adjacent technology categories should observe that some of these dynamics, particularly the adversarial brand-credibility dynamic with AI marketing claims, are now appearing in their own categories as generative AI adoption accelerates.
What Durable Cybersecurity Businesses Are Built to Become
The endpoint security category in 2026 looks fundamentally different from the one Cylance entered in 2014. Microsoft Defender for Endpoint, distributed via Microsoft 365 E5 bundling, reached approximately 28.6 percent market share in calendar 2024 according to IDC, up from 25.8 percent the prior year. CrowdStrike held approximately 14.2 percent. SentinelOne, Palo Alto Networks Cortex XDR, Trend Micro, and Sophos rounded out the leader tier. Cylance, under Arctic Wolf's Aurora Endpoint Security brand, exists as part of someone else's managed XDR offering. The single-product endpoint AV thesis on which Cylance was founded is no longer commercially viable as a standalone proposition. The market has consolidated to a small number of platform vendors, each running a multi-product Falcon-like or Singularity-like architecture, with the lower tier of the market increasingly absorbed into Microsoft's bundled offering.
This consolidation has predictable consequences. Procurement budgets are concentrating with fewer vendors. Net retention rates at the top of the market are well above 110 percent because platform expansion deals are growing faster than seat counts. The economic value of best-of-breed point products is compressing rapidly as bundled platforms reach feature parity in adjacent categories. The companies that win the next five years will be the ones that succeed at extending into security operations, identity threat detection, cloud security posture management, AI security, and SaaS security posture management, the same modular extension pattern CrowdStrike and SentinelOne have been running. The companies that lose will be the ones that cannot extend, either because their architecture cannot support it, their capital base will not fund it, or their cultural posture cannot execute it.
Cylance, in its Cylance years, had the architecture problem, the capital problem after the BlackBerry deal, and arguably the cultural problem. Three out of three. The 2024 outcome, a $1.4 billion acquisition price written down to a $160 million sale, is what happens when all three constraints bind simultaneously.
The broader takeaway for cybersecurity business leaders and tech company executives is this. In categories where platform compounding works, and most enterprise software categories now have platform compounding dynamics, the strategic question is never "do we have a better product." It is "do we have an architecture, a capital base, a team, and a brand posture that can extend the better product into a multi-product platform over a ten-year horizon." Cylance's founders answered the product question correctly in 2012 and then failed every subsequent architectural and strategic question. CrowdStrike and SentinelOne answered the product question correctly and then mostly answered the architectural and strategic questions correctly too. The combined gap between answering the product question and answering the platform question correctly is approximately $80 billion of enterprise value at current market capitalizations.
That gap is the price of mistaking a wedge for a moat. It is the price every executive should be willing to pay to think carefully about which one they actually have.
Cylance Won the Feature but Lost the Platform
Cylance did not fail because its founders were wrong about machine learning, and it did not fail because its acquirer was incompetent in any general sense. It failed because a sequence of individually defensible decisions, sell early to a strategic acquirer, optimize for pre-execution model accuracy rather than telemetry breadth, market the technology with asymmetric confidence, treat the testing community as adversaries, ship a single product rather than a modular platform, accept BlackBerry's operational and capital constraints, combined into a strategic posture that could not survive a public market that repriced cloud-native cybersecurity at multiples its founders had not anticipated. Each decision looked reasonable in isolation in 2018. Together they produced an outcome in which the company that arguably invented modern AI antivirus had to be carved out of a slow-growth parent and resold to a managed detection vendor for a tenth of its original purchase price.
The harder thing to internalize, for executives in any technology category, is that the same pattern is available to make at any moment in their own companies. Strategic acquisition offers arrive at peaks. Public market windows close. Architectural choices made early constrain product roadmaps for a decade. Marketing postures cultivated in the wedge years become liabilities in the platform years. Test results that look unfair in 2016 set Gartner positioning in 2024. Founders who cannot tolerate the parent company's cultural texture leave within twelve months, and their institutional knowledge leaves with them.
The lessons from Cylance generalize because the dynamics that defeated Cylance generalize. Wedge features in a category with strong adjacent demand will lose to platforms. Local architectures in a category with strong network effects will lose to cloud-native ones. Asymmetric marketing claims in a category with active adversarial researchers will produce credibility hits the brand cannot absorb. Premium strategic acquisitions by culturally misaligned parents at the peak of a private-market cycle will underperform comparable public-market exits over a five-year horizon. Independent testing relationships are permanent stakeholder relationships, not tactical ones. Channel economics matter as soon as mid-market demand exceeds enterprise demand. Capital strategy is product strategy in capital-intensive R&D categories.
Stuart McClure and Ryan Permeh built one of the most important pieces of cybersecurity technology of the 2010s. They sold it for $1.4 billion in cash, which was a real outcome for them, their team, and their investors. The technology they built is now part of Arctic Wolf's Aurora platform, which will be a viable product in the managed XDR category for years to come. By any normal Silicon Valley standard, the founders won. The company did not. The distinction is the most useful one in this story, and the most important one for the next generation of cybersecurity and technology executives to internalize before they make the same trade.
The hardest discipline in technology strategy is to recognize, in the moment of greatest commercial momentum, that the moat being celebrated is actually a feature on a ten-year clock. Cylance celebrated the feature. CrowdStrike and SentinelOne built the moats. The bill arrived in February 2025 for $160 million, paid in cash plus a small piece of private equity, and the books closed on the company that should have been the platform leader of the AI antivirus category but was, in the end, the cautionary opening chapter.