CrowdStrike 2024: trusted security software can be concentration risk
A faulty update to widely deployed security software took out a substantial part of the world's computing in hours.
There was no attacker. The software was doing exactly what it was designed to do, which is run with deep privilege on millions of machines and update quickly. That combination is what makes it effective and what made the failure global. Anything installed everywhere with high privilege is concentration risk regardless of its purpose.
More on Real incident lessons
- Equifax: knowing about a vulnerability is not knowing it is patchedThe list said five
- Target: supplier access showed why third-party portals need strong segmentation from sensitive systemsThe partitions stop short
- Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
- Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transferThree answers, and it moves
- British Library: recovery can outlast initial disruptionThe outage was the short part
- Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
