On a typical day, cybersecurity solutions hum in the background, diligently protecting businesses from the myriad threats that seek to exploit vulnerabilities. But what happens when an entity you rely on for security faces its own significant outage? CrowdStrike’s service disruption halted air travel, impacted healthcare, and cripped businesses worldwide. And now that the issue has been largely resolved, this technology-related incident provides invaluable lessons for organizations and cybersecurity professionals alike.
Here is what we learned from the CrowdStrike outage and how these lessons can bolster our approach to cybersecurity resilience.
- Redundancy Isn’t Just for Power Supplies
The CrowdStrike outage highlighted the critical importance of having operational redundancy built into your cybersecurity strategy. While CrowdStrike is known for its robust security measures, no system is infallible. For organizations relying on a single cybersecurity vendor (or any vendor that controls critical systems), it’s vital to have a backup plan. This might mean employing a multi-layered approach with additional security solutions or having alternative measures in place to ensure continuity during outages.
Actionable Tip: Regularly assess and update your incident response, business continuity, and disaster recover plans to include contingencies for temporary loss of access to primary security services. Consider implementing secondary solutions or integrating multiple vendors to spread the risk.
- Communication Is Key
During the outage, one of the primary concerns for businesses was the lack of timely and transparent communication from CrowdStrike. Effective communication during an impactful event, incident, or breach can significantly impact how well organizations can respond and recover. Clear, prompt updates help in managing expectations and planning the appropriate response strategies.
Actionable Tip: Develop a communication plan that outlines how, what , and when you will inform stakeholders and employees about impactful disruptions. Ensure this plan includes guidelines for frequency and content of updates and designate a point of contact for related communications.
- Test Your Preparedness
The outage underscored the importance of regularly testing your incident response, business continuity, and disaster recovery capabilities. Even if your organization has a well-documented plan, it’s only as good as its execution. Regular drills and simulations can help ensure that your team is ready to act effectively during an actual disruption outage or security breach.
Actionable Tip: Schedule periodic tabletop exercises to test your team’s readiness. Include scenarios that mimic various types of outages, including those involving your primary cybersecurity tools, to identify and address potential weaknesses in your response strategies.
- Diverse Threat Detection and Response
Relying solely on one security tool or vendor can leave gaps in your defenses, especially if that tool experiences a failure. The CrowdStrike outage serves as a reminder of the value of a diversified security approach. Combining multiple layers of threat detection and response mechanisms can provide a more comprehensive security posture.
Actionable Tip: Evaluate and integrate a variety of security tools and technologies that complement each other. This might include endpoint detection and response (EDR) systems, network security solutions, threat intelligence platforms, and privacy enhancing technology to enhance your overall defense.
- Understanding the Limitations of Technology
Even with the best tools and practices, technology has limitations. The CrowdStrike outage illustrated that no system is perfect, and issues can arise despite sophisticated design and implementation. Organizations should be aware of these limitations and prepare accordingly.
Actionable Tip: Foster a culture of forward-thinking, continuous learning, and adaptation within your security team. Stay informed about the latest developments in cybersecurity technology and practices and remain adaptable to changes and new threats.
- The Human Factor in Security
Lastly, the outage emphasized the role of human factors in managing operational incidents. While technology is crucial, human judgment and decision-making are equally important. Training and empowering your team to handle crises effectively can make a significant difference.
Actionable Tip: Invest in ongoing training for your IT, operational, and security teams. Encourage them to stay current with industry trends and best practices, and support them in developing problem-solving skills that are critical during an outage.
- An Outage Brings New Risks
The CrowdStrike outage crippled businesses and created the perfect scenario for a cyber-attack. It didn’t take long for bad actors to exploit those affected by the outage with spear-phishing campaigns, social engineering, and targeted cyber-assaults. CrowdStrike users were starved for communication and updates, creating the ideal scenario for these bad actors to lure targets into downloading a fraudulent CrowdStrike Crash Reporter tool as a ZIP file with a trojanized InnoSetup installer.
Actionable Tip: Don’t trust incoming communications blindly, verify them with your trusted Account Rep before clicking on or downloading anything. Make sure you invest in a robust cybersecurity strategy that includes training employees to recognize social engineering and phishing attempts. Encourage employees to take the time to observe their surroundings so they can make informed decisions.
- Protect Critical Data at All Costs
This may be the most important lesson. Mistakes happen, even in a highly controlled, automated, check-and-balance environment. Most operations can recover from a temporary outage, although it’s inconvenient and potentially expensive. If your business faces a Blue Screen of Death (BSOD) or other outage that leaves you locked out of critical systems, you want to know that—if nothing else—your data is secure and remains under your control.
Actionable Tip: By fully encrypting your data in all states—at rest, in transit, and in use—you ensure that even if there is an outage or an incident, your most valuable asset is locked down. Consider a searchable encryption solution like SAFE for the ultimate peace of mind.
The CrowdStrike outage serves as a poignant reminder that even the most reliable cybersecurity solutions can face disruptions. By learning from this incident and incorporating these lessons into your security strategy, you can enhance your organization’s resilience against future challenges. Embrace redundancy, improve communication, test your preparedness, diversify your tools, understand technology limitations, and invest in your team. And above all else, ensure your data is always encrypted. In doing so, you’ll be better equipped to navigate the complexities of cybersecurity and safeguard your digital assets with greater confidence.
