Case Study: CrowdStrike Outage of July 2024
SimplyPut Consulting
Business and Technology Consulting, Transformation and Enablement
On July 19th, 2024, US based cybersecurity company CrowdStrike distributed a faulty update to its security software that caused widespread problems with computers running Microsoft Windows. As a result, about 8.5 million systems crashed and were unable to properly restart in what has been called “the largest outage in the history of information technology” by The Guardian?and “historic in scale” by the New York Times.?
What Happened?
The CrowdStrike outage?was caused by a faulty configuration update to the CrowdStrike Falcon sensor software running on Windows PCs and servers. Specifically:?
The issue affected systems running Windows 10 and Windows 11 with the CrowdStrike Falcon software installed. It primarily impacted organizations rather than personal Windows PCs.?
CrowdStrike reverted the content update at 05:27 UTC, and devices that booted after the revert were not affected. However, the impact was already widespread, causing what has been called the largest outage in the history of information technology.
This incident highlights the potentially far-reaching consequences of a seemingly minor software bug in critical security systems organizations use worldwide. Your organization needs to be prepared!?
What Could Your Company Do to Mitigate the Issue?
Simply Put Consulting can help your organization to prepare for an event like the CrowdStrike outage and develop contingency plans. Organizations should implement a comprehensive strategy that includes immediate and long-term measures. Here are key steps to consider in the short term when an issue arises:?
领英推荐
However, it is the long-term strategies that will help you sleep at night. ?These can include: ?
The CrowdStrike outage reminds us of the complexities and challenges in cybersecurity. Please speak with Simply Put Consulting about implementing these strategies. Companies can better prepare for and respond to IT outages, ensuring minimal disruption to their operations and maintaining trust with their stakeholders.?https://simplyput.com/contact-us/
#SPC #TeamSPC #Cybersecurity #Strategies #BusinessContinuityPlan #BPC #Procedures #SecurityPolicies
References:?
CrowdStrike Statement: https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/?
Dev Community Assessment: https://dev.to/shishsingh/the-great-fall-decoding-the-crowdstrike-microsoft-outage-of-july-2024-19bo?
?
Enabling Growth & Impact with Salesforce @ Coastal
7 个月Business Continuity Plans are usually pushed as a non-urgent item on the list of priorities. Great to call it out here as a key action item.
Senior IT Engineering Leader
7 个月I just want to add one vector here. This is NOT just a CrowdStrike/Microsoft problem. The xz Hack showed that these types of issues can arise in other operating systems as well: https://thenewstack.io/the-xz-hack-reveals-a-looming-8-8-trillion-infrastructure-disaster-hidden-in-plain-sight/