What CrowdStrike's biggest announcements mean for security teams — and how Consortium turns them into a plan
CrowdStrike Fal.Con 2026 highlighted a fundamental shift in cybersecurity: AI-powered attacks now occur at inference speed, leaving security teams little time to respond manually. Here's how CrowdStrike is using frontier AI research, agentic security operations, runtime enforcement, and identity controls to help organizations defend against this new generation of threats -and how Consortium's Concierge approach turns that vision into a quantified, board-ready plan for our clients.
In his annual Fal.Con keynote, CrowdStrike CEO George Kurtz has always tracked breakout time - how quickly an adversary can move laterally from a compromised machine to the rest of a network. But the agentic AI era changes the math entirely. Malicious AI agents now execute attacks autonomously, at inference speed, effectively erasing the metric. Attacks happen almost instantly, and human defenders no longer have time to manually triage, respond to, and contain a breach.
"For years, I stood on the stage like this one, and I tracked this number called breakout time… We call that machine speed. We were wrong. I was wrong. This was human speed with better tools, and breakout time is over. Attacks now happen at inference speed. And when an attacker has inference speed, there is no breakout time. There's actually no time at all to deal with these attacks."
— George Kurtz, CEO at CrowdStrike
NVIDIA CEO Jensen Huang joined Kurtz's keynote to underscore the shift and make the case for bringing frontier AI directly to security teams.
"We're at an inflection point in cybersecurity for obvious reasons. We have now had agentic AI, the ability to automate attacks, and the attacks on companies are going to grow exponentially. This is the beginning of a new age of cybersecurity. On the one hand, the adversaries are going to be more armed than ever. On the other hand, all of you are going to be more armed than ever."
— Jensen Huang, CEO at NVIDIA
If breakout time is truly over, human-speed security operations can no longer keep up. The innovations announced at Fal.Con 2026 laid out CrowdStrike's vision for what comes next -autonomous defense, runtime visibility, and agent-specific identity controls, built so defenders can respond at machine speed too.
Threat actors increasingly use AI to automate reconnaissance, exploitation, and lateral movement. To keep up, security teams need AI that learns from adversaries and anticipates new attack techniques before they're used.
CrowdStrike introduced SafeMind, an agentic system that brings offensive and defensive AI together, developed through CrowdStrike's Cyber Superintelligence Lab. The system consists of:
CrowdStrike built these models on NVIDIA Nemotron open models, using CoreWeave's AI Cloud for training and inference. By pitting Red Tempest and Blue Solano against each other, SafeMind continuously tests and strengthens its own defenses, and the harnesses are designed to work with other frontier and open-source models so organizations keep flexibility and cost control.
"The basic framework of SafeMind — an adversarial model acting on a digital twin of the environment, with a defender model in a continuous cat-and-mouse loop, eventually learning how to secure itself — applies to robotics, edge computing, enterprise computing, and just about everything."
— Jensen Huang, CEO at NVIDIA
The agentic SOC
The SOC of the near future shifts from analysts investigating individual alerts to teams orchestrating and governing a fleet of specialized AI agents. CrowdStrike announced the next evolution of its agentic SOC, powered by Charlotte AI AgentWorks, to handle attacks occurring at inference speed -deploying coordinated, multi-agent investigations across endpoint, identity, SaaS, cloud, and network environments.
AgentWorks gives teams a no-code way to build, customize, and deploy hyper-specialized security agents in plain English, grounded in the Falcon platform's real-time telemetry and each organization's own data. Humans stay in control through approval gates and audit logs, while the agents themselves handle the machine-speed work of triage and response.
Runtime AI agent security
As AI agents take on more authority, organizations need visibility into what those agents are doing in real time, not just where they exist. CrowdStrike launched Falcon Guardian, a dedicated AI Detection and Response (AIDR) capability focused on runtime -the exact moment an agent turns a prompt or a piece of poisoned data into a system action.
Because agentic AI relies on autonomous tools to modify files and execute commands, waiting on post-event logs is a losing strategy against inference-speed attacks. Guardian's Agent Graph fuses agent prompts and tool calls directly with core Falcon endpoint telemetry, so teams can map their entire agent fleet, surface shadow AI, and block malicious behavior as it happens.
Securing agentic identity
Identity is becoming the primary control plane for AI. Most identity systems still treat AI agents like static service accounts or API keys, letting them inherit broad, permanent permissions they can abuse at machine speed. CrowdStrike's Agentic Identity Provider (Agentic IdP) closes that gap, working alongside Falcon Guardian's discovery to automatically register new agents into a single authoritative directory and issue each one a cryptographically verifiable identity.
Instead of permanent credentials, Agentic IdP brokers short-lived, tightly scoped tokens that grant only the access a task actually needs, and it maintains end-to-end attribution back to the human who owns the agent. Even if an agent is compromised, it can't be weaponized to move laterally or exfiltrate data unnoticed.
Adapting to machine-speed attacks takes more than new tools -it takes a strategy for adopting AI securely, governing agentic identity, modernizing operations, and cutting the complexity that slows every response down. That's the Concierge approach Consortium brought to five sessions on the Fal.Con mainstage this year, each one tackling a different piece of the puzzle above and each one grounded in a real client outcome, not a hypothetical.
Deploy the Agents
Kenny Rogers, Ali Arshad, Trever Falconi, and Lee Robare opened with the same breakout-time data behind Kurtz's keynote -29-minute average breakout, 89% more AI-enabled attacks year over year -and made the case that hiring more analysts doesn't scale against an exponential threat. The value: a field-tested adoption path for Charlotte AI, AgentWorks, and Falcon AIDR, illustrated through Seaboard Foods' own deployment. Lee Robare's framework -monitor, tune ruleset by ruleset, then earn enforcement -gives clients a way to adopt agentic AI without breaking the business on day one.
From Multiple Disparate Tools to a Unified Platform
John Starnes and Matt Minter quantified a problem every CISO feels but few can put a number on: agent sprawl. In a Consortium-led rationalization engagement for a Fortune 500 client, the stack held 45+ security products, 19 of them redundant. Consortium's assessment turned that sprawl into a board-ready financial model -$9.1M+ in annual savings, including $7M+ in endpoint licensing alone -and a phased Assess-Consolidate-Implement roadmap RWJ's Dominic Hart used to get there without a coverage gap. That's the value: rationalization isn't a cost exercise, it's the on-ramp to the agentic security program the board is already asking for.
The ROI Reckoning
This session is Consortium's clearest expression of the Concierge approach: quantify the risk before the board has to ask. John Starnes and Dylan DePaul walked through MTM -Metrics That Matter, Consortium's proprietary Cyber Risk Quantification platform, built on 400K+ real-world breach claims across 16 risk categories. The value customers Jonathan Sabatini, Jacquelyn Hemmerich, and Robert Guinn described on stage: insurance renewals backed by actuarial-grade posture evidence, platform spend defended in dollars instead of adjectives, and a board conversation that starts with a number instead of a guess.
How to Catch AI Identity Attackers Before the Impact
Kenny Rogers, Brett Dzik, Neil Schloth, and Jacquelyn Hemmerich tackled identity -82% of 2025 attacks were malware-free, 35% of cloud intrusions trace to valid account abuse -with a deception-technology playbook built on Falcon Identity Protection. The value: honeytokens carry a 100% true-positive rate by definition, and teams that deploy them see 60% faster detection, turning a 29-minute breakout window into an alert that fires the instant it's touched -a low-cost, high-confidence control Consortium helps clients stand up in weeks, not quarters.
From Myth to Mission: Securing the AI-Powered Enterprise
Kyle Villano moderated Rebekah Wilke, David Ehn, and Rich Santoriello in a CISO panel that pressure-tested the AI hype cycle against real insurance loss data -Chubb's 2025 large claims of $2.2M to $4.4M, a 53%-and-rising US cyber loss ratio. The value: a working, defensible language for talking about AI risk with the board and with carriers, before a claim forces the conversation. It's the same discipline MTM brings to every Consortium engagement -replacing “AI is probably changing our risk” with a number leadership can act on.
Fal.Con 2026 made one thing clear: organizations can no longer rely on human-speed processes to defend against inference-speed attacks. As AI agents become more deeply embedded across enterprise environments, security teams need new approaches to operations, runtime protection, and identity governance.
The organizations that come out ahead will be the ones that can adopt AI securely while keeping visibility, control, and resilience intact as the threat landscape keeps changing. That's the outcome Consortium's Concierge approach is built to deliver: quantify the risk, reduce it deliberately, and hand leadership an informed decision instead of a guess.
On Tuesday evening, Consortium took over S Bar for Secure Connections, an open social bringing together customers, partners, the CrowdStrike team, and the wider security community. No panels and no agenda — just the security practitioners who spend their days on opposite sides of a vendor relationship talking to each other as peers. For a week built around inference-speed threats, an unhurried evening turned out to be the right counterweight.
Wednesday evening was deliberately smaller. The Closed Door Dinner seated CISOs and senior security leaders together for candid, peer-level conversation about what's working, what's changing, and what's next — the kind of discussion that only happens when nobody is presenting and nothing is being recorded.
The themes echoed what played out on the mainstage all week: how to adopt agentic AI without inheriting unmanaged risk, how to defend platform spend in a tightening budget cycle, and how to have a board conversation about AI risk before a claim forces it.
Thank you to everyone who stopped by the booth, joined a session, or pulled up a chair at one of these evenings. The familiar faces and the new ones both made the week.