By Kim L. Jones
The recent CrowdStrike incident gives us a great opportunity to look at the impacts of third-party risk.

What Happened?
CrowdStrike, a leading provider of endpoint security solutions, recently released a software update which crippled Microsoft-based systems.1 The update contained an error that caused Microsoft systems to fail upon booting, more colloquially known as a “blue screen of death” (BSOD) error. Microsoft estimates that over 8 million Windows devices were impacted worldwide, causing rippling impacts in multiple industries (such as travel) and costing companies billions in losses.2

Why It Matters.
The CrowdStrike outage reminded us of two important truths:
1. “Best in class” does not equate to “flawless” or “incapable of error.”
In its 13-year history, CrowdStrike has pushed thousands of updates to millions of systems—most without incident. Assuming that a stellar track record equates to proof that something cannot go awry is, at best, optimistically inaccurate. It is essential that organizations realistically plan for failures in such a way that the impact on their infrastructures is minimized.
2. Standardization, even on a best-in-class platform, comes with its risks.
CrowdStrike’s proliferation in the market is a testament to the quality of the product, but it is also a direct contributor to the scale of the recent event. Organizations should consider this when centralizing multiple critical services with a single service provider.
"The average data breach in the higher education and training sector costs $3.7 million according to a 2023 IBM report."

What Should Leaders Do?
There are a handful of things organizations should consider doing:
Understand your third-party risk. Engaging third parties to run portions of your infrastructure does not eliminate risk within your environment. Indeed, the financial and reputational risks associated with a third-party outage may be yours alone to bear. While the CrowdStrike issue might have been at fault, Delta (for example) bears the financial and reputational impact.3 Leaders should fully understand the total potential impacts (not just the technological ones) of a third-party incident, including those impacts that are not covered by your institution's insurance.
Stagger update schedules. Automatic updates are convenient and ensure deployment throughout the enterprise. Segmenting the deployment schedule so that a single malformed software update does not topple all systems simultaneously is possible. Less critical “failover" systems can be updated hours ahead of critical systems to see if there is an unexpected issue. This gives you time to troubleshoot the situation before deployment to more critical assets.
"According to a report from SecurityScorecard and the Cyentia Institute, “98% of the 230,000 organizations they analyzed had a relationship with a third party that had suffered a breach in the past two years.”
Test software updates. Like any vulnerability patch, new software is inherently risky to a system’s functionality. Test updates before deploying within your environment.
Test your incident management plans. Assuming you have a documented incident management plan (Hint: if you don’t, you should), you should not be learning how it works during a live event. What you do during the early stages of an incident can help reduce the event’s impact. Taking time to document roles and rehearse actions will help you identify gaps in planning and respond more efficiently when the unexpected happens.
Federal Trade Commission (FTC) Updates

Recently, Federal Trade Commission (FTC) rules have impacted colleges and universities. One piece of FTC legislation is the "Safeguards Rule," which requires the development of an "information security program" to protect sensitive data. The rule further mandates that any Title IV- participating institution follow specific guidelines to maintain eligibility for federal student financial aid.
Like banks, colleges and universities maintain and handle significant amounts of sensitive financial data. The spirit of the FTC rule aims to protect this data, which results in additional risk and compliance requirements similar to those in the financial industry.
https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/
https://www.cybersecuritydive.com/news/crowdstrike-cost-fortune-500-losses-cyber-insurance/722396/
https://www.yahoo.com/news/delta-faces-investigation-following-crowdstrike-194935594.html
www.ibm.com/downloads/cas/E3G5JMBP