Accedere's Perspective on the CrowdStrike Incident
Published 08/05/2024
Editorial Note: The lessons learned and changes that may result from this incident may take quite some time to fully understand. CSA is providing a platform for member experts to weigh in on this issue. The opinions of this article represent those of the member, not those of CSA.
Written by Ashwin Chaudhary, CEO, Accedere.
On July 19, 2024, Microsoft users around the world were hit by a massive outage. The dreaded “Blue Screen of Death” (BSoD) popped up on screens worldwide. This error screen, indicative of a system crash, meant that the operating system could no longer run safely.
The Cause
The outage was traced back to an update from cybersecurity firm CrowdStrike. On July 18, CrowdStrike, an independent cybersecurity company, released a software update that began impacting IT systems globally. The issue was not a cyber-attack, but a defect found in a single content update for Windows hosts. CrowdStrike’s Falcon Sensor software, designed to prevent computer systems from cyber-attacks, was identified as the culprit.
The Impact
The outage caused widespread disruptions and chaos, affecting approximately 8.5 million of Windows devices globally, which is less than one percent of all Windows machines. While the percentage was small, the broad economic and societal impacts reflect the use of CrowdStrike by enterprises that run many critical services.
The Microsoft outage had a significant impact on various sectors globally. Here are some of the specific sectors that were affected:
- Major airlines like Delta, Allegiant, and Ryanair, as well as airports such as Heathrow, Luton, Edinburgh, Gatwick, Stansted, and others in Berlin, Tokyo, and Delhi experienced disruptions. Flights were grounded globally, causing delays and cancellations.
- Four of Govia Thameslink Railway's brands, Southern, Thameslink, Gatwick Express, and Great Northern, reported major IT problems with their services.
- The banking sector was also impacted, although the specific banks affected were not mentioned.
- Telecommunications companies were among the sectors hit by the outage.
- Media broadcasters were knocked off the air due to the outage.
- The outage also affected supermarkets, although specific names were not provided.
- The healthcare sector, including hospitals and GP services, faced disruptions.
- Shops were also among the businesses that faced disruptions due to the outage.
Resolution
Microsoft advised affected users to restore their Windows 365 Cloud PC to a known good state prior to the release of the update and directed them to some online instructions. On July 19, 2024, CrowdStrike’s CEO also stated that the issue had been identified, isolated, and a fix had been deployed.
Conclusion
Although the global outage has been fixed, its residual impact continues to affect some Microsoft 365 apps and services. This incident serves as a reminder of the fragility of our interconnected digital world and the importance of robust cybersecurity measures.
Although CrowdStrike claims it was not a security incident, the incident occurred due to lack of security knowledge and measures which impacted many sectors globally. This incident could help individuals and organizations to follow industry best practices followed globally and improve their security posture, for which regular security training, assessments, and audits are recommended.
About the Author
Ashwin Chaudhary is the CEO of Accedere, a Data Security, Privacy Audit, Technical Assessment and Training Firm. He is a CPA from Colorado, MBA, CITP, CISA, CISM, CGEIT, CRISC, CISSP, CDPSE, CCSK, PMP, ISO27001 LA, ITILv3 certified cybersecurity professional with about 22+ years of cybersecurity/privacy and 40+ years of industry experience. He has managed many cybersecurity projects covering SOC reporting, ISO audits, VAPT assessments, Privacy, IoT, Governance Risk, and Compliance.
Related Articles:
When a Breach Occurs, Are We Ready to Minimize the Operational Effects
Published: 11/08/2024
How to Simulate Session Hijacking in Your SaaS Applications
Published: 10/24/2024
CSA Community Spotlight: Guiding Industry Research with CEO Jason Garbis
Published: 10/09/2024