CrowdStrike has been named Frost & Sullivan’s 2026 Company of the Year for Identity Threat Detection and Response, a recognition that lands at a useful moment for the cybersecurity market. Identity is no longer just about employees, passwords and privileged admin accounts. It now includes service accounts, SaaS identities, machine credentials and increasingly autonomous AI agents. CrowdStrike says its Falcon Next-Gen Identity Security business has surpassed $520 million in ending ARR, up more than 34% year-on-year.
That figure gives the award commercial weight. It also underlines why identity security is becoming one of the most contested layers in enterprise defence. Traditional identity management was built around relatively static permissions: assign a role, approve access, review it later. That model starts to break down when AI agents can access data, call APIs, interact with other agents and operate across cloud, SaaS and endpoint environments.
CrowdStrike’s argument is that identity must become continuous and context-aware. Its platform is designed to discover human, non-human and AI identities, expose overprivileged access, and dynamically grant, adjust or revoke permissions based on risk and business context.
Related reading: CrowdStrike’s 2026 Global Threat Report: Why breakout time has collapsed to 29 minutes
What zero standing privileges actually means
“Zero standing privileges” sounds like security jargon, but the principle is simple: users and agents should not permanently hold powerful access just because they might need it later. Instead, access is provisioned just in time, used for a specific task, continuously evaluated, and revoked immediately after. CrowdStrike describes this as combining just-in-time access with real-time risk enforcement.
The approach is especially relevant as AI agents become operational actors. Reuters reported in January that CrowdStrike agreed to acquire SGNL for $740 million to strengthen continuous identity controls for human, machine and AI identities.
The Frost & Sullivan recognition also sits alongside CrowdStrike’s wider May push. Project QuiltWorks has expanded as a coalition for securing frontier AI risk, while Falcon OverWatch for Defender brings CrowdStrike’s managed threat hunting to Microsoft Defender environments without requiring customers to rip out existing endpoint deployments.
The message is clear: in the AI era, adversaries do not always break in. Increasingly, they log in.