Microsoft-CrowdStrike Outage: A Cautionary Tale and How DORA Can Help Financial Services Be Ready
David Roldán Martínez
Integrations Technology & Governance Strategic Advisor | APIs | AI | Smart Digital Ecosystems ?? Innovation Evangelist | Tech Writter ?? ??!???ds??d ????ou? ?o?? ??!|??? ?no? ??s no? d|?? ! '!? pu? s!d? ?u!sn
Last week's global technology outage, triggered by a faulty CrowdStrike software update on Microsoft Windows systems, sent ripples of disruption across various industries. Financial services were hit particularly hard, with banks and other institutions facing issues like:
These disruptions resulted in both financial losses and reputational damage for financial institutions. Lost productivity, transaction delays, and customer dissatisfaction can all take a toll.
The DORA Advantage: Building Resilience
While the recent outage served as a wake-up call, a new European Union (EU) regulation called the Digital Operational Resilience Act (DORA) – coming into effect in January 2025 – offers a path forward for the financial sector. DORA aims to improve the industry's resilience against ICT (Information and Communication Technology) disruptions, including cyber threats and software malfunctions.
I don't want to extend on diving deep into the regulation, but let me mention its five main pillars because it will help us to understand the importance of adopting DORA:
On the other side, the types of financial institutions DORA regulates include:?
Now, let's analyze why a DORA-compliant financial service company wouldn't have suffered the evil effects of the outage. The regulation recognizes that firms are increasingly vulnerable to threats in their supply chains, so DORA also applies to providers of critical ICT third-party services (CTPPs) including cloud, software, data analytics, and data center providers.
While the exact cause of the logic error remains under investigation, it highlights the importance of rigorous testing before deploying software updates, especially those impacting critical security software.
领英推荐
As far as it is known, the outage was caused by a faulty update from a cybersecurity firm called CrowdStrike that malfunctioned on Microsoft Windows systems:
So, how adopting DORA's principles could have helped financial institutions navigate the Microsoft-CrowdStrike outage more effectively seems quite straightforward:
While specific data isn't yet available, industry analysts estimate the outage could cause tens of billions of dollars in economic damages, with a significant portion impacting the financial sector. Lost productivity, failed transactions, and customer dissatisfaction all contribute to these potential losses.
Beyond DORA: Additional Considerations for Financial Institutions
While DORA provides a strong foundation for building operational resilience, financial institutions can take further steps to solidify their defenses:
By adopting a proactive and multifaceted approach, financial institutions can move beyond simply complying with DORA to becoming truly resilient organizations. This will not only safeguard them from future outages but also position them as leaders in an increasingly digital financial landscape.
Conclusions
The Microsoft-CrowdStrike outage serves as a stark reminder of the vulnerabilities within our interconnected technological world. However, DORA offers a roadmap for financial institutions to strengthen their defenses and emerge more resilient against future disruptions. By adhering to DORA's regulations, financial institutions can build stronger operational resilience. This translates to:
I help organizations in finding solutions to current Culture, Processes, and Technology issues through Digital Transformation by transforming the business to become more Agile and centered on the Customer (data-driven)
4 个月Agree, David Roldán Martínez. This outage underscores the critical need for robust IT resilience. DORA can be a powerful framework, but its success hinges on cultural shifts and a holistic view of technology risk.
Productor y Estratega de Marcas Personales: Creo el escenario perfecto para tu éxito al integrar método, talentos y tecnología. Enfócate en lo esencial, desarrolla tu valor, impacta vidas y vive la vida que mereces.
4 个月Lo ocurrido nos ayuda a comprender cuanto dependemos de la tecnología. Por suerte, hay muchos talento con propósito para avanzar en estos desafíos. Lo que falta a veces son las inversiones ya que pensamos que a nuestro metro cuadrado no le pasará nada.. hasta que pasa. Saludos David Roldán Martínez Un día a la vez, con gratitud y hacia adelante Siempre. ??
The root cause of CrowdStrike disaster: Microsoft driver certification bypass. Here explained in Spanish: https://lnkd.in/dqXzUKex Technical details in English: https://lnkd.in/dgu9m_Hq