By Kim L. Jones
The recent CrowdStrike incident gives us a great opportunity to look at the impacts of third-party risk.
What Happened?
CrowdStrike, a leading provider of endpoint security solutions, recently released a software update which crippled Microsoft-based systems.1 The update contained an error that caused Microsoft systems to fail upon booting, more colloquially known as a “blue screen of death” (BSOD) error. Microsoft estimates that over 8 million Windows devices were impacted worldwide, causing rippling impacts in multiple industries (such as travel) and costing companies billions in losses.2
Why It Matters.
The CrowdStrike outage reminded us of two important truths:
“Best in class” does not equate to “flawless” or “incapable of error.”
In its 13-year history, CrowdStrike has pushed thousands of updates to millions of systems—most without incident. Assuming that a stellar track record equates to proof that something cannot go awry is, at best, optimistically inaccurate. It is essential that organizations realistically plan for failures in such a way that the impact on their infrastructures is minimized.
Standardization, even on a best-in-class platform, comes with its risks.
CrowdStrike’s proliferation in the market is a testament to the quality of the product, but it is also a direct contributor to the scale of the recent event. Organizations should consider this when centralizing multiple critical services with a single service provider.
The average data breach in the higher education and training sector costs $3.7 million according to a 2023 IBM report.
According to a report from SecurityScorecard and the Cyentia Institute, “98% of the 230,000 organizations they analyzed had a relationship with a third party that had suffered a breach in the past two years.”
What Should Leaders Do?
There are a handful of things organiz