Global Chaos! The CrowdStrike Outage.

Global Chaos! The CrowdStrike Outage.

Do computers already run the world?? CYBER WAR could be the next major threat to national security!

Last Friday, the world experienced a massive, unprecedented computer outage caused by a defective “routine” software update to Microsoft Windows customers issued by CrowdStrike, an Austin, Texas-based cybersecurity technology company ironically designed to prevent cyber-attacks.? Mac and Linux hosts were not affected.

In only a few hours, companies and industries worldwide were crippled, as over 8.5 million machines were affected causing frozen blue screens referred to as the “Blue Screen of Death!”

For example:

  1. Travel: The big 3 airlines, United, Delta, and American grounded flights in the early hours as over 5000 US flights were canceled on Friday, over 2000 on Saturday, and over 500 at the time of writing this article on Sunday Morning.? American is the only carrier back on schedule for now.? There have been reports of airline agents handwriting boarding passes.? Even bus stops had blank blue screens!
  2. Healthcare: Many hospitals have been forced to cancel ALL elective surgeries, walk-ins, and routine appointments, and some life-saving surgeries have even been postponed.? 911 calls were adversely affected!
  3. Banks: There have been reports from traders at JP Morgan Chase and other financial institutions of orders that could not be executed.?
  4. Chain Restaurants: Starbucks mobile ordering crashed (Dunkin Donuts survived) and McDonald’s in Japan closed almost a third of their stores for the day.
  5. Governments: The Dutch and UAE foreign ministries reported massive IT (information technology) outages.? In the U.S., downed court systems delayed trials for hours, including Harvey Weinstein’s.?

This is a scary situation as it was allegedly caused by an accident.? What if it was planned, how much worse would it be?? According to Richard Clarke, former White House Counter-Terrorism Czar, Putin has already used this technology to plant a “spy package” into a software update for a company called Solar Winds, which affected over 10,000 government and private-sector machines that were not detected for 9 months.?

Unfortunately, there is little regulation, if any, on software; believe it or not, CrowdStrike cannot be sued!

My Suggestions for CrowdStrike and other large firms:

  1. Test your Updates Before releasing them to the masses:? I spoke with tech experts who say technology can be developed to both pre-test these software updates before rollouts and or abort them during problem rollouts!
  2. Do NOT send it to everyone at the same time: This isolates potential problems and the ripple effects of them.
  3. Large Firms Need to Diversify: Large firms and perhaps even mid-size firms should consider spreading their risk by using 2 types of software.

During the chaos last Friday, cybersecurity agencies noticed upticks in copy caters and phishing.? Scammers immediately pounced on the unsuspecting and unprepared public!? Within hours, new domains had surfaced aiming to “dupe” users and designed to steal user data and breach their devices.

My suggestions for individuals:

  1. Turn Off Automatic Updates:? The CrowdStrike outage has taught us the latest isn’t always the greatest when it comes to operating system updates. Unless the update addresses a critical security vulnerability wait a week or two to see if other users are experiencing problems.
  2. Check your Malware:? This is the time to check or add malware protection for your computers.
  3. Consider DuckDuckGo Search Engine: Google uses what is called “cookies” to track your searches and purchases.? Consider adding or using DuckDuckGo in addition to or in lieu of Google.? While Google is the superior search engine, DuckDuckGo does NOT track any of your queries.
  4. Hover Over Email Sources Before Opening: Scammers have gotten more sophisticated using emails and texts.? Take your mouse or trackpad and “hover over” the email sender to see if you recognize the email address before opening and responding.

The bottom line is if one company’s “single content update” software bug can trigger a “worldwide internet outage,” then back up and checks and balances measures need to be taken immediately!

Allison Buhler

Technology Executive, Innovator

3 个月

I appreciate that you touch on the responsibility of individuals; the greatest failing here, by far, is reflected not within CrowdStrike itself but within the broader economy. The wide-spread nature of the issue and the horribly inadequate recovery process seem to indicate that ignoring (or misunderstanding) best practices is more common than following them. Vendor recommendations are not an excuse for inadequate management of the vendors themselves by their customers. We must take responsibility for the systems we control!

回复
Junaid Abro

Designer & Content Writer | Wordpress Developer | SEO Expert | learning Back End

4 个月
回复

Watching this #CrisisResponse has been like watching a slow-moving #RiskManagement train wreck. A Company like CrowdStrike should have a measurement of its aggregate contingent business interruption exposure across its entire customer base, across industry sectors, and for the critical 20% of clients that make up 80% of its revenue, etc. Knowing that number means 1. This loss can never happen, 2. Better crisis response, communication and accountability would be in place, & 3. The company would have adequate Cyber & Network Security Liability Insurance Coverage, including coverage for customer's contingent business interruption exposure for data breaches, hacks, system failure, etc. As well as adequate Directors & Officers Insurance, Errors & Omissions, etc. The apparent failure of 1. and 2. suggests there may not be much in the way of insurance recovery for all the impacted clients and that this could very well be a "business killer" loss for CrowdStrike. This is why cyber insurance is hard to insure and will now be much harder to insure. If your house is on fire, no one else reading this is likely to be impacted. Cyber exposure spreads like a pandemic and we all remember how much darn fun that was!

回复
Shannon Hicks -Reverse Mortgage Commentator

President: Reverse Focus, Inc. ? Video Commentator ? Blogger ? Podcaster ? Reverse Mortgage Enthusiast ? P: 800-805-9328

4 个月

Good insights!

要查看或添加评论,请登录

社区洞察

其他会员也浏览了