WTF happened with the CrowdStrike Outage
First Off, who (or what) is CrowdStrike?
Similar to Norton, Symantec, or McAfee – CrowdStrike is a cybersecurity company that provides endpoint protection, threat intelligence, and incident response services against malware, ransomware, and advanced threats
They had made significant gains in the industry and were looked to as a top-of-market option for Cybersecurity software; they are one of the largest players in the Cybersecurity game and their software is located on millions of computers and servers
Who has CrowdStrike?
Crowdstrike would be purchased and deployed by either your internal I.T. team or via a 3rd Party Consultant as part of their cybersecurity package.
Government, Private, and everyone in-between had Crowdstrike so the update caused outages from airlines and TV broadcasts to small businesses and manufacturing.
What happened with CrowdStrike?
They done fucked up…
The CrowdStrike outage was caused by an automatic update from CrowdStrike
The update was intended to enhance security but instead created a mismatch in input values which led to an out-of-bounds memory read, causing system crashes across most devices running the CrowdStrike Falcon sensor
A Blue Screens of Death (BSOD) showed up on most, if not all, of the computers with their software
After the crashes, CrowdStrike quickly issued a detailed root cause analysis and provided steps to the public on how to get the computers back up and running
Crowdstrike committed two cardinal sins
- They ran an update without properly testing it
- They ran that update on a FRIDAY!!!
What is next for Crowdstrike?
A long look in the mirror, a re-jiggering of their process, and a 40% drop in their stock which will likely only continue as contracts come up for renewal
How does this affect you?
Some might take this as proof that having cybersecurity is just as risky as not having it… but the recovery timeframe for this incident was within a day as techs had an easy path to recovery
The recovery from a hack, however, could take weeks and cost millions in legal fees, lost contracts and embarrassment
We are in a new age of technology where you can wake up and all your systems could be down, so have a plan in place in place for when your computers/emails/files are taken down for prolonged periods of time
WTF happened with the CrowdStrike Outage
First Off, who (or what) is CrowdStrike?
Similar to Norton, Symantec, or McAfee – CrowdStrike is a cybersecurity company that provides endpoint protection, threat intelligence, and incident response services against malware, ransomware, and advanced threats
They had made significant gains in the industry and were looked to as a top-of-market option for Cybersecurity software; they are one of the largest players in the Cybersecurity game and their software is located on millions of computers and servers
Who has CrowdStrike?
Crowdstrike would be purchased and deployed by either your internal I.T. team or via a 3rd Party Consultant as part of their cybersecurity package.
Government, Private, and everyone in-between had Crowdstrike so the update caused outages from airlines and TV broadcasts to small businesses and manufacturing.
What happened with CrowdStrike?
They done fucked up…
The CrowdStrike outage was caused by an automatic update from CrowdStrike
The update was intended to enhance security but instead created a mismatch in input values which led to an out-of-bounds memory read, causing system crashes across most devices running the CrowdStrike Falcon sensor
A Blue Screens of Death (BSOD) showed up on most, if not all, of the computers with their software
After the crashes, CrowdStrike quickly issued a detailed root cause analysis and provided steps to the public on how to get the computers back up and running
Crowdstrike committed two cardinal sins
- They ran an update without properly testing it
- They ran that update on a FRIDAY!!!
What is next for Crowdstrike?
A long look in the mirror, a re-jiggering of their process, and a 40% drop in their stock which will likely only continue as contracts come up for renewal
How does this affect you?
Some might take this as proof that having cybersecurity is just as risky as not having it… but the recovery timeframe for this incident was within a day as techs had an easy path to recovery
The recovery from a hack, however, could take weeks and cost millions in legal fees, lost contracts and embarrassment
We are in a new age of technology where you can wake up and all your systems could be down, so have a plan in place in place for when your computers/emails/files are taken down for prolonged periods of time