Better Decisions Brief: Responding to the CrowdStrike IT Outage

Better Decisions Brief: Responding to the CrowdStrike IT Outage
July 19, 2024 3 mins

Better Decisions Brief: Responding to the CrowdStrike IT Outage

CrowdStrike Outage

While the impact of today’s CrowdStrike outage is yet to be fully understood, it serves as an opportunity for C-suite and other business decision-makers to think through technology dependencies and the steps necessary to respond to this outage – as well as to mitigate related risks in future.

Key Takeaways
  1. This is potentially one of the largest IT outages ever experienced by the global economy.
  2. It has been linked to a security update from CrowdStrike’s Falcon software, which then impacted Microsoft systems. Based on public reporting to date, there is no evidence to suggest that this situation is the result of an external compromise.
  3. CrowdStrike’s CEO, George Kurtz has said “the issue has been identified, isolated and a fix has been deployed” – but the incident will raise serious questions for cyber professionals.

Four Initial Learnings from the CrowdStrike Outage

  1. Businesses should evaluate, update and test their business continuity and/or disaster recovery plans regularly. Using risk analytics, companies should evaluate the financial impact of an event as part of this process.
  2. Organizations should understand the dependencies and supply chain for critical infrastructure, and ensure they have adequate protection through contractual terms, insurance, or tested and resilient backup plans.
  3. If a downtime event occurs, or there are concerns that an IT or security event has occurred, businesses should notify their insurance brokers and partners promptly to determine what coverage might be available.
  4. Businesses should review their regulatory reporting obligations in light of the incident.

Next Steps

You can read more about this event in our Cyber Solutions update on the CrowdStrike outage blog post.

While the situation is still ongoing, the IT outage is a reminder of the dynamic nature of technology and the importance of robust incident response protocols.

Should you wish to talk to Aon about responding to this event, please contact a colleague on our cyber leadership team.

Key Contacts

Asia-Pacific
Adam Peckman
[email protected]

Europe, Middle East & Africa
David Molony
[email protected]

Latin America
Sergio Torres
[email protected]

North America
Brent Rieth
[email protected]

General Disclaimer

The information contained herein and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information and use sources we consider reliable, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. This information is not a replacement for legal, tax accounting or other professional advice and no one should act on such information without appropriate professional advice after a thorough examination of the particular situation.

Terms of Use

The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.

More Like This

View All
Subscribe CTA Banner