CrowdStrike named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Download report
Customer Story

How Ashton Woods Homes Secures Its SaaS-First World with Falcon Shield

When David Cochran, Director of IT, joined Ashton Woods Homes eight years ago, the company had already embraced a fully SaaS-based architecture with no on-premises servers, networks, cloud workloads, or data centers to manage. As the company grew organically from 700 to 1,400 employees, so did its reliance on SaaS solutions.

While the SaaS-first model still powers the business today, it has also reshaped its risk profile. “Everything we do is SaaS-based,” said Cochran. “We don’t manage a wide area network or physical infrastructure. Security for us means protecting our endpoints and SaaS applications, with identity as the nexus between the two."

To safeguard its modern environment, Ashton Woods turned to CrowdStrike Falcon® Shield, the industry’s most comprehensive SaaS security posture management (SSPM) solution. Falcon Shield continuously monitors configurations, users, devices, and even non-human identities — including AI agents — across 180+ applications. This gives teams the visibility, context, and control they need to stop breaches across the SaaS stack.

“What really hit home was the breadth of capability that Shield has,” Cochran said. “It wasn’t just surface-level visibility. Each check came with context and remediation guidance. It was like having a recipe book for SaaS security.”

Within weeks, Falcon Shield surfaced dozens of failed configuration checks across critical apps like Microsoft 365, Salesforce, Intune, and Okta. Each finding came with step-by-step remediation and clear context, allowing Cochran’s small team to strengthen security posture without specialized expertise or time-consuming audits.

“Falcon Shield helped us get more value out of the tools we already had and confidence that we weren’t missing something crucial.”
David Cochran, Director of IT
Ashton Woods Homes

Continuous Visibility That Drives Real Results

One of the clearest examples of this visibility came from integrating Falcon Shield with Zscaler. Ashton Woods had used Zscaler for nearly two years and was confident in its deployment … until Shield revealed dozens of unseen configuration gaps.

“Some of them were just simple checkboxes, things like blocking unsupported browsers or disabling risky tunneling,” said Cochran. “They had never come up during our implementation or on calls with the account team.”

Addressing those gaps improved Ashton Woods’ Zscaler configuration posture from 72% to 96% in just a few days. “Shield turned what we thought was a completed project into one that was actually secure,” Cochran said. “That visibility is priceless for a small team.”

Falcon Shield also helps Ashton Woods stay ahead of change. “New checks appear regularly, sometimes in response to real-world incidents like OAuth vulnerabilities, and that keeps us aligned with emerging risks,” he added.

The tool tracks configuration drift, flags expired dismissals, and automatically alerts Cochran when a setting changes or new checks are added — critical for catching things like lingering user access after an employee leaves the company, a common route for SaaS-based attacks. 

“We never just sweep issues under the rug,” he said. “Shield ensures every dismissed risk has an expiration and a reason. That’s how we stay accountable.”

Smarter Threat Detection for SaaS

Falcon Shield’s Threat Center consolidates alerts from every connected SaaS app into a single pane of glass, correlating user behavior, device data, and SaaS events across the environment.

“With the Threat Center, I can see all alerts from Microsoft, Okta, Salesforce … plus Shield’s own detections … in one place,” Cochran said. “Those synthesized alerts are the real differentiator. They surface issues the native tools don’t flag and help me prioritize what to address first.”

Instead of chasing alerts across dozens of portals, Cochran and his team focus on what matters most: identifying misconfigurations before they become incidents and detecting threats early in the kill chain.

Unified Defense for a Lean Team

With only three people managing security operations, Ashton Woods has relied on CrowdStrike Falcon® Complete Next-Gen MDR to handle endpoint protection while Falcon Shield secures the SaaS stack.

“Falcon Complete means I don’t have to worry about endpoint threats,” said Cochran. “Falcon Shield gives me that same peace of mind on the SaaS side. Together, they protect everything that matters.”

By combining managed detection and response with continuous SaaS security, Ashton Woods gains full-stack visibility without the need for a large internal SOC. “We’ve reduced our manual work dramatically,” Cochran added. “That allows us to focus on strategic initiatives instead of firefighting.”

Built for the Future of SaaS Security

Since CrowdStrike’s acquisition of Adaptive Shield, Cochran has watched the Falcon Shield roadmap accelerate with the addition of new integrations, deeper coverage, and tighter alignment with other Falcon platform modules like CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Falcon® Identity Protection.

“The acquisition has been nothing but positive,” he said. “The resources and innovation going into Falcon Shield are already paying dividends. For us, it’s about visibility, context, and control … and Shield delivers all three.”

For Ashton Woods, SaaS security isn’t a separate discipline, it’s the foundation of how the business operates. “It’s not just a tool, it’s how we stay secure in a SaaS-first world,” Cochran concluded.

Challenges

  • Lean IT team responsible for securing SaaS applications
  • Limited visibility into SaaS configuration drift and identity risks
  • Missed misconfigurations in mission critical apps
  • Aimed to unify SaaS posture management and threat detection into a single cohesive platform

Results

  • Improved Zscaler configuration posture from 72% to 96% in days
  • Continuous monitoring across dozens of SaaS applications
  • Proactive detection of configuration drift and expired permissions
  • Unified visibility and synthesized alerts through Falcon Shield Threat Center
  • Scaled full-stack protection with a three-person SOC

CrowdStrike Solutions

  • Falcon Complete Next-Gen MDR
  • Falcon Insight EDR
  • Falcon Shield
Contact Sales Schedule a demo