Understanding the HISTORIC CrowdStrike Outage and How to Enhance YOUR Cybersecurity Resilience.
Jen Waltz ?????????
Dynamic Senior Executive in Global Sales, Strategic Partnerships, and Channel Alliances | Proven Leader in Driving Multi-Billion Dollar Growth Across SaaS, Cybersecurity, and AI/ML Sectors 2024. MSFT, Unisys, EQIX alumni
By Jen Waltz, Vice President, Global Alternate Channels
On July 19, 2024, a significant global computer outage occurred due to a faulty sensor configuration update in CrowdStrike's Falcon cybersecurity platform. This update affected approximately 8.5 million Windows devices, causing disruptions across airlines, hospitals, and financial institutions. Although the outage impacted less than one percent of all Windows machines, its broad economic and societal impacts were significant due to these enterprises' critical services. As I write this blog post, my husband, Dr.?Aaron Waltz,?has been stranded in Calgary, Alberta, Canada, due to his flight back home cancellation.
The Cause of the Outage
According to CrowdStrike, the issue originated from a sensor configuration update released during ongoing operations. This update triggered a logic error, resulting in a system crash and a blue screen of death (BSOD) on impacted systems. A logic or semantic error is a program's source code bug that can cause abnormal application behavior or system crashes.
CrowdStrike's Falcon platform is a breach-prevention tool using cloud-delivered technologies to prevent various attacks, including malware. The platform's core functions include antivirus, endpoint detection and response (EDR), cyber threat intelligence, managed threat hunting, and security hygiene. Falcon operates with a lightweight sensor that is cloud-managed and delivered.
CrowdStrike Response and Apology
“I want to sincerely apologize directly to all of you for today’s outage.” George Kurtz, CrowdStrike’s founder and CEO.
CrowdStrike promptly apologized and began a thorough root cause analysis to understand how the logic flaw occurred and identify process improvements. Kurtz sincerely apologized for the outage and emphasized the company's commitment to preventing similar incidents in the future.
Complete coverage of CrowdStrike's boggled update and Microsoft outage aftermath
Lessons Learned and Necessary Changes
The CrowdStrike outage highlights several key areas where organizations can enhance their cybersecurity resilience:
Enhanced Incident Response Plans
Organizations must ensure that their incident response plans are comprehensive and well-practiced. Response plans include:
Implement Redundant Systems
To mitigate the impact of outages, organizations should consider implementing redundant systems and services:
Strengthen Communication Protocols
Clear communication is vital during an outage. Enhancing communication protocols includes:
Improve Monitoring and Logging
Enhanced monitoring and logging can provide better visibility and faster detection of issues:
Review and Update Access Controls
Reevaluating and strengthening access controls is crucial to minimize risks during outages:
Enhance Backup and Recovery Procedures
Robust backup and recovery procedures can ensure quick restoration of services:
Strengthen Vendor Management
Improving vendor management practices to ensure better coordination and support during incidents:
领英推荐
Invest in Cybersecurity Training
Continuous training for staff on cybersecurity best practices and incident response:
Adopt a Resilience-Focused Approach
Building a resilience-focused cybersecurity strategy that anticipates and mitigates disruptions:
Review Cybersecurity Architecture
Assessing and potentially redesigning the cybersecurity architecture to address vulnerabilities exposed by the outage:
How Kron Technologies KronPAM Could Have Helped Mitigate the CrowdStrike Outage
I will illustrate how Kron PAM (Privileged Access Management) cybersecurity could have assisted during the CrowdStrike outage; it's essential to consider PAM solutions' functionalities and advantages in managing such incidents. Here's how Kron Technologies could have helped:
Enhanced Privileged Access Controls
Rapid Incident Response
Audit and Compliance
Access Workflow Management
Risk Mitigation
Collaboration and Communication
Moving Forward
The CrowdStrike outage is a stark reminder of the importance of robust cybersecurity practices and disaster recovery planning. By implementing these changes and leveraging solutions like Kron PAM, organizations can better prepare for and respond to cybersecurity incidents, minimizing their impact and ensuring more excellent continuity of operations. This proactive approach will improve resilience and bolster overall security posture in an increasingly complex threat landscape.
If you would like more detailed information on Microsoft's response and remediation efforts, please visit David Weston's Microsoft response, 'Helping our customers through the CrowdStrike outage. '
If you want more detailed information on CrowdStrike's remediation efforts, visit the?CrowdStrike Tech Alert support page. You'll find resources, recommended fixes, and tools to identify impacted hosts here.
For more information on Kron Technologies and how our Kron PAM? Privileged Access Management Suite is known as the fastest to deploy and the most secure PAM solution in the marketplace, click here.
Reflecting on this incident and taking proactive steps can help us better prepare for future challenges. If you would like more details, please get in touch with me at [email protected].
President @ SafePC Solutions | Generative AI, IT Infrastructure, & Cybersecurity
4 个月Thanks for this very important article Jen Waltz ??????
Medicare Agency Owner. Open for business connections and always on the lookout for a better FMO
4 个月Useful tips
?? Helping people build authentic connections, powerful partnerships, and leadership | Bestselling Author | Keynote Speaker & Host | Advisor, Investor, Founder, and CEO.
4 个月excellent summary from a super smart cyber guru.
Founder and CEO @ RYTHMz Network | Taking back the cloud
4 个月This was a great read. I have a different perspective on the situation https://www.dhirubhai.net/posts/stevecopeland_techresilience-cybersecurity-leadershiplessons-activity-7220541112875147264-eMN2?utm_source=share&utm_medium=member_ios
CEO of PartnerTap | Ecosystem Co-Selling Platform | Partner Sales Growth
4 个月Great article Jen! I hope Dr. Waltz makes it home soon.