NoticiasNews

"La seguridad es requisito de la adopción de IA": CrowdStrike y Okta convierten el riesgo de los agentes en su mejor trimestre"Security Is a Requirement for AI Adoption": CrowdStrike and Okta Turn Agent Risk Into Their Best Quarter

2026-08-28

El 26 de agosto, CrowdStrike y Okta reportaron sus trimestres cerrados el 31 de julio. Ambas superaron expectativas, ambas elevaron su guía anual, y las acciones subieron más de 10 % y 19 % respectivamente en operaciones posteriores al cierre. Lo relevante no es el movimiento bursátil: es que los ejecutivos de las dos compañías señalaron exactamente la misma fuerza detrás de la demanda —el despliegue empresarial de agentes de inteligencia artificial.

Las cifras

CrowdStrike reportó ingresos de US$1,470 millones, un alza de 26 % interanual, con utilidad ajustada de 31 centavos por acción. El dato que llamó la atención de los analistas fue el nuevo ARR neto: US$332.8 millones, un aumento de 51 % interanual y muy por encima del rango de US$284–286 millones que la propia empresa había proyectado en junio. El ARR total llegó a US$5,840 millones (+25 %). El flujo de caja operativo de US$530.3 millones y el flujo de caja libre de US$377.4 millones fueron ambos récords para un segundo trimestre.

Okta entregó utilidad ajustada de US$1.05 por acción sobre ingresos de US$805 millones (+11 %). Las obligaciones de desempeño remanentes —la medida del backlog de suscripciones— subieron 17 % hasta US$4,858 millones. La compañía elevó su guía anual de ingresos, de utilidad y de flujo de caja libre.

El argumento que ambas usan

George Kurtz, fundador y CEO de CrowdStrike, enmarcó el trimestre en lo que llamó el "momento Mythos": "El mundo llegó a entender que la ciberseguridad es una necesidad para la adopción de IA. Toda empresa va a funcionar sobre IA, y asegurarla es la mayor oportunidad de mercado en nuestra historia".

Todd McKinnon, cofundador y CEO de Okta, planteó el mismo problema desde el otro extremo: cada agente "necesita una identidad confiable y controles claros sobre a qué puede acceder y qué puede hacer". Okta se posiciona como el proveedor neutral que las organizaciones pueden usar para descubrir agentes, gobernar lo que hacen y responder cuando algo sale mal.

Dave Vellante, analista jefe de theCUBE Research, resumió la lectura: "Un récord de nuevo ARR neto de US$333 millones, arriba 51 % interanual, indica que la urgencia creada por las amenazas potenciadas con IA se está convirtiendo en demanda significativa".

Lo que se está comprando en concreto

Los movimientos de producto del trimestre son más informativos que las declaraciones. CrowdStrike presentó Continuous Identity for AI Agents, que extiende la autorización consciente del riesgo a identidades humanas, de máquina y de agente. Acordó comprar los activos tecnológicos de XM Cyber, especializada en visualización de rutas de ataque y simulación ofensiva. Y amplió su coalición Project QuiltWorks —enfocada en vulnerabilidades descubiertas por IA— a la capa de infraestructura de nube con AWS.

Okta, por su parte, acordó el 30 de julio comprar Permiso Security, empresa de detección de amenazas de identidad, en una operación reportada en algo menos de US$200 millones, con cierre previsto antes de finales de octubre.

El patrón es evidente: la industria está construyendo, con dinero real, la capa de identidad y permisos para entidades no humanas.

La implicación práctica para una empresa que ya usa agentes

Conviene traducir esto a preguntas operativas, porque el problema es el mismo para una empresa de 50 empleados que para una de 50,000:

  • ¿Sabe cuántos agentes de IA operan hoy en su organización? No cuántos aprobó: cuántos existen. Un agente conectado a un sistema por un equipo sin avisar a nadie es exactamente el riesgo que estas compras buscan cubrir.
  • ¿Cada agente tiene una identidad propia o comparte credenciales con una persona? Si comparte, no hay forma de auditar quién hizo qué.
  • ¿Qué puede escribir, borrar o aprobar cada agente? El permiso de lectura y el de escritura son riesgos de órdenes de magnitud distintos.
  • ¿Qué pasa cuando algo sale mal? ¿Existe una ruta para revocar un agente en minutos, o hay que abrir un ticket?

Prudencia con el entusiasmo: la propia Okta advirtió que la contribución directa de ingresos por seguridad de IA sigue siendo temprana y probablemente no será material para su año fiscal 2027, aunque podría volverse significativa desde 2028. Es decir: la urgencia es real, pero el mercado apenas está formándose.

En TEKFENIX abordamos esto desde la trazabilidad. CumplimientoControl está construido sobre el principio de que toda acción —humana o automatizada— debe quedar registrada de forma auditable, con quién la originó, cuándo y bajo qué autorización; el mismo principio que hoy la industria está comprando a precio de adquisición corporativa. Y en Servigo365 aplicamos el mismo criterio a los agentes de atención al cliente: la IA propone y ejecuta dentro de límites explícitos, y cada paso queda registrado. Si su equipo ya desplegó agentes y todavía no definió sus permisos, ese es el punto por donde empezar.

On August 26, CrowdStrike and Okta reported their quarters ended July 31. Both beat expectations, both raised full-year guidance, and shares rose more than 10% and 19% respectively in after-hours trading. The market move is not what matters: what matters is that executives at both companies pointed to exactly the same force behind demand — enterprise deployment of AI agents.

The figures

CrowdStrike reported revenue of $1.47 billion, up 26% year over year, with adjusted earnings of 31 cents per share. The figure that caught analysts' attention was net new ARR: $332.8 million, up 51% year over year and well clear of the $284–286 million range the company itself guided to in June. Total ARR reached $5.84 billion (+25%). Operating cash flow of $530.3 million and free cash flow of $377.4 million were both second-quarter records.

Okta delivered adjusted earnings of $1.05 per share on revenue of $805 million (+11%). Remaining performance obligations — the measure of subscription backlog — rose 17% to $4.858 billion. The company raised full-year revenue, earnings and free cash flow guidance.

The argument both are making

George Kurtz, CrowdStrike founder and CEO, framed the quarter around what he called the "Mythos moment": "The world came to understand that cybersecurity is a necessity for AI adoption. Every enterprise will run on AI, and securing it is the largest market opportunity in our history."

Todd McKinnon, Okta co-founder and CEO, framed the same problem from the other end: every agent "needs a trusted identity and clear controls over what it can access and do." Okta positions itself as the neutral provider organizations can use to discover agents, govern what they do and respond when something goes wrong.

Dave Vellante, chief analyst at theCUBE Research, summarized the read: "Record net new ARR of $333 million, up 51% year over year, indicates that the urgency created by AI-powered threats is converting into significant demand."

What is actually being bought

The quarter's product moves are more informative than the statements. CrowdStrike unveiled Continuous Identity for AI Agents, which extends risk-aware authorization across human, machine and agent identities. It agreed to buy the technology assets of XM Cyber, which specializes in attack path visualization and offensive simulation. And it widened its Project QuiltWorks coalition — focused on AI-discovered vulnerabilities — to the cloud infrastructure layer with AWS.

Okta, for its part, agreed on July 30 to buy identity threat detection company Permiso Security in a deal reported at just under $200 million, due to close before the end of October.

The pattern is unmistakable: the industry is building, with real money, the identity and permissions layer for non-human entities.

The practical implication for a company already running agents

It is worth translating this into operational questions, because the problem is the same for a 50-person company as for a 50,000-person one:

  • Do you know how many AI agents operate in your organization today? Not how many you approved: how many exist. An agent wired into a system by one team without telling anyone is exactly the risk these acquisitions are meant to cover.
  • Does each agent have its own identity, or does it share credentials with a person? If it shares, there is no way to audit who did what.
  • What can each agent write, delete or approve? Read permission and write permission are risks of entirely different magnitudes.
  • What happens when something goes wrong? Is there a path to revoke an agent in minutes, or does someone have to open a ticket?

A note of caution on the enthusiasm: Okta itself warned that direct revenue contribution from AI security remains early and is unlikely to be material to fiscal 2027, though it could become significant from 2028 onward. In other words: the urgency is real, but the market is barely forming.

At TEKFENIX we approach this through traceability. CumplimientoControl is built on the principle that every action — human or automated — must be recorded auditably, with who originated it, when, and under what authorization; the same principle the industry is now buying at acquisition prices. And in Servigo365 we apply the same criterion to customer service agents: AI proposes and executes within explicit limits, and every step is logged. If your team has already deployed agents and has not yet defined their permissions, that is where to start.

← Volver al blog← Back to blog