Skip to content

How a CrowdStrike Software Update Caused the Global IT Outage

Person working at a desk with multiple computer monitors displaying code and data in an office with city view at dusk.

Our world increasingly depends on digital connections that usually operate silently, out of sight. How, then, could one software update disable half the internet?

The global IT outage on 19 July was a sobering illustration of how exposed we are to technology failures.

Caused by one defective software update issued by cybersecurity company CrowdStrike, the incident had devastating consequences for airlines, media organisations, banks and retailers across the world, especially organisations running Microsoft Windows operating systems.

Labelled the "largest IT outage in history", the event underlines both the vast network of IT links supporting digital infrastructure and the wide-ranging fallout that can follow when one element fails.

Initial airport delays rapidly developed into mass flight cancellations. Problems with airline systems affected more than timetables: they also disrupted global supply chains dependent on air freight, revealing the many interconnected layers of modern IT ecosystems.

At the same time, broadcasts at many television and radio stations were disrupted, while supermarkets and banks saw their operations grind to a halt.

Early assessments indicate that the disorder originated with an update to CrowdStrike's Falcon Sensor security software, deployed on Microsoft Windows operating systems.

Employees at organisations using CrowdStrike encountered the "blue screen of death" - an error screen signalling that a system has crashed - when attempting to sign in.

CrowdStrike global IT outage and geopolitical dependence

As well as exposing the largely unseen dependencies underpinning the digital economy and society, the outage drew attention to their geopolitical significance.

The greatest effects were felt in countries closely connected to Microsoft and CrowdStrike. By contrast, companies in nations such as China, whose IT infrastructure is comparatively insulated and tightly controlled, seem to have suffered less disruption.

Amid rising geopolitical tensions over recent years, China and an increasing number of other countries have deliberately built their own digital infrastructure and cybersecurity capabilities, potentially limiting the impact of this event.

China's emphasis on indigenous technology and on lowering its reliance on foreign technology may likewise have reduced the effects on its systems.

The episode is a sharp reminder that dependence on technology can become a geopolitical weakness. State authorities must increasingly weigh not only the economic implications of IT partnerships, but their strategic and geopolitical consequences too.

Recovery and implications

The way affected industries have responded to the crisis demonstrates both the strengths and weaknesses in their security and disaster-recovery arrangements.

The central fault has been identified and is reportedly fixed. Yet the gradual recovery now under way will reveal the considerable difficulties involved in re-establishing continuous services across complex, tightly interlinked digital ecosystems.

It is especially striking that, despite earlier warnings - including the 2018 TSB IT migration disaster that affected millions of customers at the UK bank - no staggered software rollout was used.

Skipping this basic but vital IT management measure revealed the fragility of systems that many had assumed were resilient.

The incident has also prompted serious questions about the robustness of Windows operating systems and of the CrowdStrike cybersecurity protections designed to secure them.

It further exposed the strategic dangers of relying on one technology provider. This worldwide outage illustrated the importance of diverse technology partnerships for national security and economic stability, while also intensifying concerns that hostile states could exploit such weaknesses.

The event will lend fresh urgency to international cybersecurity cooperation and policy action.

As services start to stabilise and return, the outage should be a warning for IT specialists, business executives and policymakers alike.

There is a clear and urgent need to review - and potentially redesign - current cybersecurity strategies and IT management practices. Strengthening systems so they can withstand major disruption must become a priority.

The global IT outage is both a timely warning and a pivotal moment for debates about digital resilience and the future governance of technology in business, infrastructure and policy.

Is the world ready for AI?

Another question remains unanswered: if a single software fault can bring down airlines, banks, retailers, media organisations and more worldwide, are our systems prepared for AI?

We may need to put greater investment into software reliability and methodology instead of rushing to release chatbots. An unregulated AI sector could be a recipe for disaster, particularly as geopolitical tensions intensify.

Although embracing emerging technologies such as AI and blockchain is essential, the fundamentals must also be right.

Cybersecurity teams must make sure core IT management and maintenance procedures are robust, dependable and capable of dealing with everything from a cyberattack to an ordinary software update.

The insights gained from this incident will undoubtedly shape future approaches to IT infrastructure development and crisis management.

Feng Li, Chair of Information Management, Associate Dean for Research & Innovation, Bayes Business School, City, University of London

This article is republished from The Conversation under a Creative Commons licence. Read the original article.

Comments

No comments yet. Be the first to comment!

Leave a Comment