Mandiant and CrowdStrike partner to help customers investigate and mitigate threats; Mandiant will begin deploying CrowdStrike's tools
Joseph Menn / Washington Post :
Context & Ripple Effects
CrowdStrike has spent years assembling its platform through acquisition — starting with its zero trust buy of Preempt Security and continuing with SaaS and AI-security deals — while holding roughly 15% of global security software per Gartner. The missing piece was distribution into the incident-response moment itself.
That is what this partnership supplies: Mandiant, the response firm whose investigators led the Snowflake breach notification effort touching roughly 165 organizations, will now deploy CrowdStrike's tools during customer engagements, wiring the industry's go-to IR team directly into its telemetry.
First-order effects
- Mandiant's incident responders arrive at breaches with CrowdStrike's detection stack already deployed, making the two firms' joint customers the immediate beneficiaries of faster investigate-and-mitigate cycles.
Second-order effects
- Competing EDR vendors lose their most credible neutral channel into breach engagements, pressuring rivals to lock up IR partnerships or acquisitions of their own — the same build-versus-buy logic behind CrowdStrike's Preempt, Adaptive Shield, and Pangea deals.
Third-order effects
- If IR firms keep standardizing on one vendor's tooling, breach response consolidates around platform ecosystems rather than independent consultancies, with the responder's tool choice shaping which telemetry and threat intelligence dominate post-incident analysis.
The trend: Cybersecurity is consolidating from point products into end-to-end platforms, with incident-response partnerships becoming the distribution mechanism that locks enterprises into a single vendor's stack.