― Advertisement ―

The New Luxury is a Better Life

For globally mobile citizens, the new luxury is not merely what one owns, but how well one lives, across borders, generations and experiences.
HomeThe Largest IT Outage in History? CrowdStrike Incident and Its Legal Implications

The Largest IT Outage in History? CrowdStrike Incident and Its Legal Implications

An IMGW News Report:

A botched update by security software maker CrowdStrike has led to what may be the largest IT outage in history, with experts predicting recovery could take weeks. Businesses are grappling with widespread disruptions after a faulty software update from CrowdStrike’s Falcon system caused numerous Windows PCs and servers to crash.

Users experienced the notorious ‘blue screen of death’ upon rebooting their Windows devices, grounding flights, postponing hospital appointments, and interrupting broadcasts worldwide. CrowdStrike acknowledged that an update to its Falcon software was responsible for the bug.

“This unprecedented failure is particularly startling given CrowdStrike’s strong reputation as a frontline defence against cyberattacks,” remarked an industry analyst. The only fix involves manually deleting the faulty update on each device, a process that could span days or weeks for companies with extensive networks or limited IT staff.

Is it really business as usual? Adding to the complexity, the IT outage’s impact on anti-money laundering software and other third-party reliant applications remains unclear. These systems, crucial for financial transactions, travel vetting, and due diligence processes involved in investment-by-migration (IM) programmes, depend on timely data. Outages can cause financial transaction delays, travel disruptions, and processing hold-ups, highlighting the critical importance of reliable data sources.”

Millions of devices may need manual intervention. Critical machines, such as CEOs’ laptops, are likely already fixed, but many ordinary employees might face extended wait times for repairs, warned an IT expert.

CrowdStrike, based in Austin, Texas, serves over 29,000 business customers, including more than half of the Fortune 500. The incident highlights the significant risk posed by concentrated reliance on a few key software providers, noted an industry analyst.

The global ripple effect underscores vulnerabilities in the interconnected IT ecosystem. “The vast interdependence and concentration risk in this market are starkly evident,” the analyst added. Such dependency on major software vendors necessitates a reassessment of the economic and regulatory landscape, according to a financial analyst.

In response to the crisis, CrowdStrike CEO George Kurtz apologised to customers, assuring them that the incident was not a cyberattack and that their systems remain protected. However, security researchers caution that cybercriminals might exploit the chaos for phishing scams, impersonating CrowdStrike or Microsoft agents.

The root cause appears to be a lapse in testing, suggested a computer science lecturer. “It seems someone simply got a bit of code wrong,” he said. The incident raises broader questions about the balance between rapid updates and system resilience. “There’s a trade-off between speed and due diligence,” commented an IT expert.

Is it really business as usual?

Adding to the complexity, the IT outage’s impact on anti-money laundering software and other third-party reliant applications remains unclear. These systems, crucial for financial transactions, travel vetting, and due diligence processes involved in investment-by-migration (IM) programmes, depend on timely data. Outages can cause financial transaction delays, travel disruptions, and processing hold-ups, highlighting the critical importance of reliable data sources.”

Similarly, investment-by-migration programmes, which require rigorous background checks and compliance with international regulations, might experience processing delays, affecting applicants and administrative workflows.

Legal Implications of the CrowdStrike Incident

This incident raises significant legal questions regarding liability and contractual obligations. Businesses need robust IT change management processes to handle frequent updates securely. Including clauses for update testing and approval in IT contracts can mitigate such risks.

The concentration risk of relying on a few key providers is now evident. The EU’s Digital Operational Resilience Act (DORA), effective from January 2025, will require financial services to assess and manage this risk comprehensively.

Business continuity and disaster recovery (BCDR) planning is crucial. The CrowdStrike incident highlights the need for well-prepared BCDR plans, regularly updated and tested.

Lastly, understanding cyber and business interruption insurance is vital. Businesses should know their coverage limits and ensure policies cover non-malicious incidents like this. For vendors, liability exclusions and financial caps in contracts can prevent overwhelming liabilities.

As the CrowdStrike saga unfolds, it underscores the critical need for rigorous testing protocols, robust planning, and comprehensive risk management in the IT sector.

If you found this article of interest, IMGW News recommends the following from its recent publications – Enjoy!

  1. Navigating the AI landscape: Insights from Compliance and Risk Management Leaders
  2. Onboarding Unleashed: How AI is Redefining Wealth Management and Investment Migration