About a year ago, on CrowdStrike's own numbers, roughly 11 to 12% of phishing emails got a click. Michael Sentonas says the figure is now over 60%.
The security industry spent two decades warning that attackers would one day find vulnerabilities and weaponize them faster than any defender could respond. Sentonas's position is that the day has arrived, and that the tool which brought it is free to download and free to run.
"The adversary does not care."
Sentonas is CrowdStrike's president. He was the company's chief technology officer before that, and the go-to-market organization, the product and engineering teams, the researchers and the threat hunters all report to him.
I listened to the full interview so you can skip it. 15 minutes of audio, 9 minutes of reading.
Here are the 10 takeaways that matter.
👤 Guest: Michael Sentonas, president of CrowdStrike and its former chief technology officer, who runs go-to-market, product, engineering, research and threat hunting
🎙️ Hosts: John Coogan and Jordi Hays, who present TBPN live on X and YouTube every weekday
📰 Published: 1 September 2026 on YouTube (TBPN)
🔴 YouTube | 🟣 Apple Podcasts | 🔗 Show notes | ⏱️ 15 min
Key Takeaways
Phishing emails now get clicked more than five times as often as a year ago The old advice was to look for bad English, and Sentonas says that tell is gone
The single biggest gift to attackers has been the arrival of good open-weight models Run inside their own environment, a tuned model is invisible until the first attack lands
A defender has to be right every time and cannot switch the business off to manage it
Change control and regulation are costs only one side of the fight pays
The buyers are trying to fund tokens out of budgets that were already spent
Stolen encrypted data that never resurfaces was taken for a reason, and that reason may be quantum
Sentonas expects more vulnerabilities and more attacks, not a settling down
1. What the president runs
The interview opened on the job itself.
Sentonas has both halves of the company reporting to him. "So go to market reports into me." He added the product and engineering team, the researchers and the threat hunters
He came up through the product side. "I think my background started through the product side of the organization. I was the CTO of the company for quite a while."
His argument for holding both is that neither works alone. He said you can build the best technology in the industry, and if you cannot sell it, cannot talk about the value, and customers cannot deploy it and keep themselves safe, then it is irrelevant
He said he works closely with George Kurtz, who had been on the show minutes before, and who has a further group of engineering and research people reporting to him
2. The token line item
Asked what customers are actually worried about when security is getting this much attention, Sentonas went straight to the budget.
Every buyer has a business to run that is not cybersecurity. "You're building cars. You're building houses." The security spend competes with that, not with an unlimited pot
What changed in 2026 is that a new cost arrived without a budget line. Sentonas said organizations came into the year trying to work out how to find tokens to pay for everything the business was doing
He described the overrun as routine rather than exceptional. "So at the end of every month, they just realized that they spent 20,000 more than they should have" — a figure he attached to a per-employee basis
CrowdStrike's answer is a procurement vehicle rather than a discount. He pointed at CrowdStrike Flex as the way customers buy, and said the pitch covers deployment and day-to-day operation as much as price
The sales motion is explicitly a consolidation one. "Here's a product. We're gonna try to take two out." He corrected himself upward: "It's one in two out, three out."
3. Right every time or never
A host put the asymmetry to him: the defender has to succeed every time, the attacker once in a hundred thousand tries.
Sentonas accepted the framing and added the constraint that makes it worse. "Every organization can't get it wrong." They also cannot stop the business while getting it right
Perfect security is available and nobody will buy it. "It's easy to get it right a 100%" — his own completion of the thought was "If you turn off everything."
He said a chief executive will not accept security that slows down browsing or blocks the AI tools staff want to use, which is the real limit on how much protection can be switched on
4. Rules only defenders follow
The defender's process burden is not shared by the other side. Sentonas listed change control, regulatory guidelines and internal process as things the defender must observe, then: "Attacker doesn't care about any of that."
He has made the point to European audiences directly. Speaking at a conference there, he told a room proud of leading the world on AI regulation: "The adversary does not care."
A host's response was that attackers are already breaking the law, so a further rule changes nothing for them
He tied it back to money. "You can't just pour everything into tokens." The IT budget has the same ceiling, which is why he frames CrowdStrike's job as getting the most out of a fixed spend
5. Open weights, tuned quietly
Asked whether the real problem is the speed of AI adoption rather than raw model intelligence, Sentonas agreed and named the reason.
The models attackers use are downloadable and interchangeable. "They can go and get a Chinese model. They can go and get a model effectively from anywhere that they run inside their sort of framework."
Running it privately is what removes the defender's warning. "And because they're running it in their environment, they can customize it in a way that you don't know what they're doing." His conclusion: "And then the first time they use it is the first time you have to deal with it."
It is also cheap, because there is no bill. "When they run it internally, they don't have the cost of sending you the tokens and everything else." What they need instead is hardware
Compute is a real constraint, but only for the small operator. "Depends on the adversary, you know. The kid at home is gonna be compute constrained." A well-funded, well-structured nation state is not
He used the conference itself as evidence of the response. "That's why there was a packed arena this morning. That's why Jensen came out to talk about what they can do."
6. The prediction came true
The scenario the industry has been describing for two decades has arrived. "Look. We've talked about this for twenty plus years." The talk was of a future in which "Where attackers are finding vulnerabilities and they're weaponizing them at a speed that you're just not gonna be able to deal with."
His verdict on where that future sits. "We're here now."
The reason it landed, on his account, is access rather than invention: the adversaries get everything the defenders get, and the advancement in open-weight models is the best thing that has happened to them
7. Small business, and states
Asked what governments are saying, Sentonas made the argument about the bottom of the market rather than the top.
The exposure is concentrated where the resources are not. He said the world's economy runs on small business, then: "They don't have the resource. They don't have dedicated people. They don't have the dollars." When something goes wrong they often do not know where to go
Governments are asking about continuity of basic services. "We need to make sure that critical infrastructure, you know, the power is on, water is flowing, you know, rubbish trucks arrive." He said examples of critical infrastructure being taken out already exist
He drew a hard line on the financial system. "We can't have banks get compromised with ransomware."
Every government conversation now opens the same way. They want to know what AI does for them, how to embrace it, and what people with malicious intent could do to them with the same open-weight models
8. Stealing data for later
A host raised the harvest-now, decrypt-later problem: adversaries taking encrypted data on the expectation that a future quantum computer will open it.
Sentonas said quantum is being asked about constantly, not ignored. "Not a day go by." Then: "A customer, a partner, an analyst, someone asks a question about quantum and what that means."
The pattern he described is data that leaves and never reappears. "A lot of the time, you see examples where attackers will basically exfiltrate all your data." Nothing surfaces afterwards
The breach notification is the tell. "And you get the email saying, yes. Your name was in clear text, but everything else was encrypted. And now you have to think in five years that might be decrypted."
His inference is about motive, not method. "Well, they didn't do it just because they wanted to have fun." Then: "So there's intent." He listed later decryption and model training as two of the possible reasons
He contrasted it with the older economics of a breach, where you could see why you were taken. When your name appears in a list, you understand that you are the person being monetized. Terabytes that nobody sells and nobody acts on is a different problem
The reputational motive is gone. Writing malware once earned credit from firms like CrowdStrike naming the technique as innovative. "Doesn't work that way anymore."
9. Phishing above 60%
The old detection advice does not work. Sentonas said the guidance used to be that an email reading as though a ten-year-old or a non-native speaker wrote it was probably not from your bank: "It was an easy telltale sign."
The rate has moved by a multiple, not a margin. "We used to say about a year ago, the click through rate in phishing was about 11 to 12%." His figure for today: "Over 60 now."
The cause is that the writing is now better than the target's. "They're written perfect. They're grammatically they probably write better than us now." He named ChatGPT and Gemini as the tools attackers learned to use
The expertise barrier has gone with it. "The thing is you grab an open weight model and you basically say, how would I carry out this attack?" The answer: "It's gonna give you the playbook."
He put the change against his own career. "I've I've done cyber since university. You don't need any of that anymore." Then: "I kind of feel like wasted youth now because you just need a model."
10. Look after the customer
The last question was about managing teams through the periods when the market decides software is finished.
His answer was a line he was given twenty years ago. "I've known George who he had on just before for over twenty years. And I remember one of the first things he ever said to me, look after the customer. Everything else takes care of itself."
He said that is what CrowdStrike falls back on when the narrative turns. "So all of this noise, you know, we just basically say, keep looking after the customer, keep innovating, keeping them safe and secure, things will take care of themselves."
He does not think the software-is-over argument had anything in it. "It didn't make any sense at all."
He rejects the newer version of it as well — the idea that models will find all the vulnerabilities and the industry will settle into a steady state: "Even today when people say, hey. All the models are gonna find all the vulnerabilities, and then we're gonna get this state of normality. No. We're not."
His forecast is the opposite of stabilization. "We're gonna get more vulnerabilities. We're gonna get more attacks. It's only gonna get harder."
Bonus Insights
A host offered that the frontier labs hold the advantage on raw model capability, and put CrowdStrike alongside OpenAI and Anthropic as organizations that could use it offensively but do not. Sentonas did not take up the comparison and answered on the asymmetry instead
Sentonas said he had "A little bit of reason" to do with the size of the conference when asked whether he was why everyone had turned up
The hosts read the 60% phishing figure back into their own news discussion after he left, treating it as the number of the day
Sentonas's bottom line is that the attacker's costs have collapsed while the defender's constraints have not moved, so the only thing left to compete on is how efficiently a security budget that was already fixed can be spent.
Products, Companies & Tools Mentioned
CrowdStrike (Sentonas runs go-to-market, product, engineering and threat hunting; CrowdStrike Flex is the purchasing vehicle he points customers at)
ChatGPT and Gemini (The tools he says attackers learned to use to write phishing emails that no longer read as fake)
Nvidia (Jensen Huang's keynote that morning is what he cites as the industry's collective answer)
OpenAI and Anthropic (Named by a host as the labs holding the capability advantage, alongside CrowdStrike, and not using it offensively)
If this was worth your time, send it to someone closer to the industry than you are.
Get the latest market chatter as it happens:

