Article Details
Scrape Timestamp (UTC): 2024-09-19 16:18:34.213
Source: https://www.theregister.com/2024/09/19/german_crowdstrike_reaction/
Original Article Text
Click to Toggle View
1 in 10 orgs dumping their security vendors after CrowdStrike outage. Many left reeling from July's IT meltdown, but not to worry, it was all unavoidable. Germany's Federal Office for Information Security (BSI) says one in ten organizations in the country affected by CrowdStrike's outage in July are dropping their current vendor's products. Four percent of organizations have already abandoned their existing solutions, while a further 6 percent plan to do so in the near future. It wasn't explicitly said whether this referred to CrowdStrike's Falcon product specifically or was a knee-jerk reaction to security vendors generally. One in five will also change the selection criteria when it comes to reviewing which security vendor gets their business. The whole fiasco doesn't seem to have hurt the company much though, at least not yet. The findings come from a report examining the experiences of 311 affected organizations in Germany, published today. Of those affected in one way or another, most said they first heard about the issues from social media (23 percent) rather than CrowdStrike itself (22 percent). The report also revealed that half of the 311 surveyed orgs had to halt operations – 48 percent experienced temporary downtime. Ten hours, on average. Aside from the obvious business continuity impacts, this led to various issues with customers too. Forty percent said their collaboration with customers was damaged because they couldn't provide their usual services, while more than one in ten organizations didn't even want to address the topic. The majority of respondents (66 percent) said they will improve their incident response plans in light of what happened, or have done so already, despite largely considering events like these as unavoidable. "There will never be a 100 percent protection against IT security incidents in the future. Nevertheless, we aim to get as close to 100 percent as possible," said Claudia Plattner, BSI president. "To achieve this, the BSI is in close collaboration with CrowdStrike, Microsoft, and other software manufacturers to improve the quality of their software and software updates. Additionally, companies must and can increase their resilience through preventive measures, making them more resistant to IT security incidents. "It is important to give users the greatest possible control over update processes. Furthermore, the survey results also show that well-practiced IT emergency concepts must be an important component of any crisis preparedness." One curiosity of the report was the focus on CrowdStrike customers' attitude towards applying security updates post-breakdown. More than half said they want to install updates more regularly, despite the speed at which updates are applied not being a relevant factor in this case. CrowdStrike pushed its faulty Falcon sensor update, in the form of a channel file, via an automatic cloud update. Even if the update was applied manually, doing so at rapid speed – before seeing how it affected other users – would have been worse for the organization, not better. Regardless, with the number of urgent patch warnings we and the infosec community dish out every week, it's probably a net positive, even if it's slightly misguided. The BSI was quick to say this survey isn't representative of the entire country, given the sample size, "but it does provide a meaningful picture of the mood for affected companies in Germany." Ralf Wintergerst, president at Bitkom, which carried out the research, said: "The IT outages and their consequences demonstrate the outstanding importance of digital technologies for our economy and society. This time it ended relatively harmlessly, also thanks to the joint efforts of businesses and authorities, with the support of CrowdStrike and Microsoft. However, it must serve as a warning for us. "We urgently need to further improve our cybersecurity and require corresponding in-house expertise in companies and authorities – only in this way can we better protect ourselves against unintended outages or targeted attacks and become more digitally sovereign." The July outage impacted organizations in multiple industries across the world from healthcare to transport, bricking 8.5 million PCs. The US House Homeland Security Committee is set to grill an exec over the debacle next week... although CEO George Kurtz will not be the one providing public testimony.
Daily Brief Summary
10% of German organizations affected by the CrowdStrike outage are changing their security vendors, with 4% already having switched and an additional 6% planning changes.
The July incident caused operational disruptions, with 48% of surveyed organizations experiencing temporary downtime averaging ten hours.
The outage damaged collaborations with customers, impacting 40% of organizations and causing service delivery issues.
Despite the significant impact, 66% of the affected organizations are planning to enhance or have already improved their incident response strategies.
A majority of respondents will revise their selection criteria for future security vendor decisions, emphasizing the lasting effect of the outage on purchasing behaviors.
More than half of the surveyed organizations intend to apply security updates more frequently, even though update speed was not a factor in this incident.
The German Federal Office for Information Security (BSI) and other entities emphasize the need for improved cybersecurity practices and resilience to prevent similar occurrences.