What comes next: Huntress hits an inflection point

In my last blog, I wrote about Huntress crossing $250M ARR. That post was about the people who got us here: the teammates, partners, customers, investors, and families who carried this thing long before it looked obvious from the outside.

This one's about where our mission must go next, and the threats we'll face if we don't better leverage partnerships, emerging tech, momentum, and our research-lab mindset. Said bluntly, the 99% of businesses most deserving of better security are at real risk if we don't quickly level up.

A force for good

A quarter-billion in ARR might sound like a feel-good revenue story. To me, it sounds like responsibility and an obligation to uphold our position as a company of consequence—one now big enough to be a real force for good (or flop like the endless startups before us).

From my perspective, I'm pumped to know we're no longer looking through a single-product lens. We can see across identities, endpoints, cloud apps, remote access tools, and the sneaky ways attackers actually move. This is a key component needed to truly challenge innovative micro-teams of cybercriminals who are just beginning to showcase how rapid, automated intrusions pivot across these domains. However, multi-product platforms simply aren't enough, and Huntress will need to move differently. We'll need to move as autonomously as possible without sacrificing efficacy.

When I think about consistently delivering compounding results in the future, it's not enough for modern security platforms to coordinate between products. Agentic- and API-powered coordination is table stakes to play against lawless adversaries. We'll need to better leverage our global telemetry and 11 years of untapped data to truly give defense the advantage. 

For instance, when we see 300 companies simultaneously compromised by a breaking global campaign, the future we're building toward is one where we can immediately inoculate millions of other organizations worldwide before the attack reaches them. That's true herd immunity. While Huntress does this today, our approaches will need to expand and evolve to stay ahead of adversary innovation.

To truly be a global force for good, Huntress had to face the reality that cybercriminals were reaching victims more quickly and efficiently than we alone could educate and protect. As a result, we're dramatically leaning into community and expanding our partner base to be the accelerant that helps us reach the 99% faster.  

This must go beyond a revenue growth strategy. The deeper our relationships grow with Microsoft, MSPs, private industry, RMM vendors, distributors, global law enforcement, and federal agencies like the FBI Cyber Division, the larger our collective impact will be. 

Speaking with Assistant Director Brett Leatherman of the FBI Cyber Division on the July 28 episode of _declassified, the spicy yet educational show we produce exposing the darkest corners of cybercrime. 

Cybercrime is organized. And it'll only get better, allowing attackers to move across platforms, businesses, and borders with ease. I expect their speed to dramatically increase. But we're getting big enough to open doors we couldn't open before, big enough to bring the right people into the same room, and big enough to share signals across the 99% in ways that'll radically change outcomes.

That's the opportunity. While there's real danger in spreading ourselves too thin, a greater danger lies ahead, and Huntress cannot rest on its laurels or obsess over perfect metrics while backsliding on our mission. I won't let that happen.

AI is a double-edged sword

There's no honest conversation about the future of Huntress without talking about AI.

The adversary was the earliest and most aggressive adopter. They're collectively building and scaling faster than they were just six months ago, and that pace is only going to intensify. So yes, Huntress will use AI. However, our approach matters and must be differentiated. 

Easy stuff: we'll continue to invest in and enhance our AI capabilities to accelerate SOC workflows, help our researchers investigate more in parallel, and pull our best people away from the repetitive work machines can handle on their own. It'll also help us keep pricing as stable and predictable as possible, something that's becoming increasingly rare in other places. Done right, AI will help us better extend our deep, in-house domain expertise and global telemetry observations to the businesses that could never hire these enterprise experts or insights. That's the upside. 

But AI has another edge, and I don't trust anyone who only talks about the sharpened one. AI can lie to you with a straight face. I'm already seeing this from AI-only security and SOC vendors (including the ones we consider to protect our own ass(ets))

Reports that look polished, full of confident language and real data/events, but if you look closer, the story takes a turn that doesn't hold up. A normal login is allegedly an advanced campaign. A real event gets wrapped in fabricated attribution. Think about the customer who believes they've been hit by something that could ruin their business, and then someone with actual expertise has to spend time pulling the thread and explaining that, though the report sounded scary and realistic, it didn't actually happen or fully make sense. That's a serious problem for this industry. 

To be clear, this isn't dunking or naming any one vendor. Huntress absolutely could make the same mistakes if we get careless. That's what makes this moment feel so ominous, and that's the double edge I need my team to respect and defend against.

An example of a vendor's AI-SOC spitting out nonsense. Huntress can't let this happen. 

As AI gets integrated into security products, buyers will have a harder time distinguishing real expertise from a machine that simply sounds confident. The people we serve don't have time to become LLM forensics experts. They just need to know what's happening, what to do next, and whether their platform can be trusted.

That's why I keep talking to my team about keeping "humans in the lead." For years, the industry standard was "humans in the loop," or a person somewhere in the chain signing off on the machine's work. That won't be good enough for what's coming. 

In order to provide the best possible security, we're doubling down on keeping humans in the lead, meaning analysts, researchers, engineers, and threat hunters will set the direction and keep the work grounded in evidence, all while AI helps them move faster. We'll use models where they help, build guardrails where we need them, and own it when we get something wrong. 

What we can't do is blindly accept whatever a machine spits out. AI has to make Huntress faster, sharper, and more agile. If it only makes us louder, we'll have failed.

Knowing the adversary inside and out

For the past 11 years, we've been able to stay ahead of cybercrime and nation-state actors, and that starts with our DNA:

  • We're deeply committed to our mission, and we're rooted in offensive cyber operations

  • Our lab-mindset enables the world's brightest security researchers to thrive at Huntress

  • And their obsession with outcome-driven innovation is the magic that wrecks hackers

Our future success depends on that DNA, and we'll have to protect it with everything we've got. This is the key to knowing the adversary inside and out.

We must stay close to the tradecraft and continue to position ourselves ahead of attacker behavior. We'll continue to follow the data, even when it tells us our first answer was wrong. We'll listen intently when partners tell us the roadmap doesn't match their reality. We won't lose any of this.

We were founded as Huntress Labs, and the "lab" will always stay in the lifeblood of this company. It's where our researchers do hands-on work, sit with real incidents, and share what they find so the whole community can benefit. 

Late nights with the lab throughout the Microsoft Exchange campaign brought together private industry and global law enforcement, resulting in a worldwide manhunt that brought a malicious hacker to justice earlier this year. 

That researcher-focused culture is our edge. It'll keep us close to the tradecraft and allow us to stay ahead of adversaries instead of chasing them. The lab has and will continue to remain the engine shaping what we build for years to come. My job as CEO is to make sure we never deviate from that.

The spirit of Huntress Labs will always be strong because attackers get to break laws. We don't. That's their advantage. Ours has to come from somewhere else: data, speed, community, and the ability to see patterns across the 99% before the next wave lands. 

We'll keep working with partners, private industry, and law enforcement in ways attackers can't. We'll impose costs when they think they don't have to pay. 

For years, an industry adage claimed defenders have to be right every time, while attackers only have to be right once. I've always thought that was lame. And it doesn't have to remain true.

One attack can protect everyone else

Even if Huntress does its job perfectly, attackers will still come for us. They'll keep evolving, abusing trusted tools and legit services while moving at machine speed. But when they do, we'll make them feel it. Not just for the benefit of one customer, but for the whole community. What we learn from one attack will be used to shut it down for everyone else before it ever has a chance to touch them.

That's how we'll keep moving. The decade of work behind us is more than just history. It's compounding interest. It's the rocket fuel that'll let us keep pace as attackers get faster and hit harder. 

As we push from 270k protected businesses toward a million and beyond, the goal is to change the calculus the whole industry has lived under. Instead of the adversary only having to be right once, they'll only get to try once before we turn what they did into protection for us all. That's the future we're building. 

We're big enough now to be a force for good, but let me be clear about how far we still have to go. There are still gaps we have to fill, and closing them is the work ahead. 

Over time, Huntress will evolve into an autonomous, end-to-end security platform that protects the 99% across every place attackers try to move. AI, in the wrong hands, will only make the fight faster and messier, but we'll use it smarter and with greater discipline. And through all of it, we won't lose the edge that got us here.

We'll always be here for the 99%. We'll always wreck hackers. And we've got a very long way to go.