
On July 19, 2024, a faulty CrowdStrike content update crashed about 8.5 million Windows machines, and over the next eleven days the company's shares fell 32%, erasing roughly $25 billion of market value. Fifteen months later F5 disclosed that a nation-state actor had held long-term access to the environment where it develops BIG-IP, its highest-revenue product, and its stock dropped almost 14% in two sessions. The point made in this source about cybersecurity PR, that its real job is making people feel safe choosing a product, can sound abstract until you follow the money through cases like these. When the company paid to prevent incidents becomes one, investors, customers and courts each send their own bill, and the record of the last three years shows how large each bill turned out to be and which parts of it management could still influence.
The asymmetry was measured more than twenty years ago. In a 2004 event study, Huseyin Cavusoglu, Birendra Mishra and Srinivasan Raghunathan found that companies announcing an internet security breach lost an average of 2.1% of their market value within two days, about $1.65 billion per incident, while firms that develop security technology earned an abnormal return of 1.36% over the same window. For a vendor, a breach at someone else's company works like a sales signal. A failure of its own is a different kind of news, because it reveals something the market normally cannot see.
Ross Anderson and Tyler Moore of Cambridge observed that most users of software, security products included, cannot tell what is vulnerable and what is not. That pushes buyers toward proxies such as brand, analyst rankings and references from peers. A working endpoint agent or firewall produces nothing visible, because its success is the absence of an event. The rare day it fails is one of the few moments when outsiders get direct evidence about quality, and investors apply that evidence to the entire installed base rather than to the damage already done.
That explains the gap between the bill and the price move at CrowdStrike. The company estimated that its customer commitment packages, the concessions it offered customers after the outage, would take about $60 million out of net new ARR and subscription revenue in the second half of its fiscal year, and it booked $33.9 million of incident-related expenses in the following quarter. The market value lost in the first eleven days was more than two hundred times the sum of those two figures. What investors priced in that stretch was the chance that thousands of security teams would decide the product itself had become the risk.
Customers reacted more calmly than the share price suggested, and the difference shows up in retention data. CrowdStrike reported gross retention of 97% in each of the three quarters after the outage. What moved was expansion: the dollar-based net retention rate was 112% as of January 31, 2025, down from 119% a year earlier, a decline that reflects both slower buying and the concessions described above. Customers kept the agent running and spent less on top of it. That pattern fits products installed deep in the stack, where replacing an endpoint sensor or a network appliance takes months and opens a security gap of its own while it happens. The discretionary layer of spending, meaning new modules, larger renewals and new customers, absorbed the shock.
The share price eventually lined up with the retention data rather than the headlines. From a pre-outage close of $343.05 it hit an intraday low of $200.81 on August 5, 2024, a 41.5% decline, then traded at a record above $406 in late January 2025, about six months after the event. In early June 2025 it closed at a record $479.17.
F5's operating results followed a shorter version of the same arc. Its October 27 outlook projected fiscal 2026 revenue growth of 0% to 4%, below the roughly 4.8% analysts had expected, and warned that customers would slow purchases while they assessed and patched their environments. The shares fell again. Then the first quarter came in at $822 million, up 7% and above the top of the company's own $730 million to $780 million guidance range, and each of the next two quarters grew 11%. During that first quarter F5 also bought back $300 million of its stock at an average price of $249, in effect a bet that the market had overestimated the damage.
A different problem appears when a company's first account of an incident does not survive its own investigation. On October 20, 2023, Okta said an attacker had used a stolen credential to get into its customer support system, and its shares closed down about 11.6%, removing roughly $2 billion of market value. Its early account put the exposure at fewer than 1% of customers, 134 in total. At the end of November, Okta told customers that the attacker had also downloaded a report containing the names and email addresses of every user of that support system.
SonicWall repeated the sequence in 2025. On September 17 it said the attack on its cloud backup service affected fewer than 5% of its firewall install base. On October 8, after an investigation with Mandiant, it said the attacker had accessed configuration backups for every customer who had used the service, and it declined to explain the jump.
Revisions like these do more damage than the added facts alone would justify, because they change how every later statement is read. Security vendors also answer to an unusually capable audience. BeyondTrust said it detected and blocked an attempt on an administrator account in its own Okta tenant on October 2 and reported it to Okta, and Cloudflare caught related activity on October 18, both before Okta went public. For customers like these, a vendor's scope estimate is an operational input that decides which credentials get rotated and which logs get searched. The exposure also travels. Cloudflare later disclosed that an access token and three service account credentials taken in the Okta incident, which it had missed while rotating thousands of others because it believed they were unused, were used in a November 2023 intrusion into its own systems.
F5 shows a milder version, with information arriving in two installments. Its October 15 filing, made after the Justice Department allowed a delay under the national security exception in the SEC's disclosure rule, described the intrusion, and its October 27 outlook described what the intrusion meant for sales. The stock fell on each. A securities class action filed afterward argues, among other things, that the first disclosure left the business impact out.
None of these companies could undo the incident once it had happened. The record does point to a handful of communication and commercial decisions that shaped how much of the first markdown stuck:
The last point cuts both ways, and the two main lawsuits show why. In January 2026 a federal judge in Texas dismissed the shareholder suit over pre-outage statements about testing, finding that investors had not plausibly shown misleading statements or intent to defraud. The Georgia case, in which Delta says the outage cost it more than $500 million, was allowed to proceed, and CrowdStrike's outside counsel responded that any damages should be contractually capped in the single-digit millions. Public contrition played well with practitioners and also became evidence, which argues for agreeing on the wording with counsel before anyone steps on stage, not for staying quiet.
For a security vendor, an incident is priced less as an expense than as evidence about the product, which is why the first markdown runs far ahead of any itemized cost. The cases here suggest that how much of it sticks depends on two things that can be measured: whether customers stay, and whether the company's first description of events holds up. Management's choices in the first weeks after disclosure shape both.