By J. Mesa
On Friday, July 19, computers around the world crashed to a blue error screen and would not restart. Airlines grounded flights. Hospitals postponed procedures. Banks, retailers, and 911 centers lost systems. No criminal caused it. A routine update from a security company did. Microsoft estimated that 8.5 million Windows devices went down. The event offers the cleanest test in years of a question every owner should answer: how does my business run when the computers do not?
What happened in the CrowdStrike outage?
CrowdStrike makes Falcon, a widely used endpoint security product. Early on July 19, 2024, the company released a content configuration update for the Falcon sensor on Windows. The update contained a defect. Windows computers that received it crashed and then crashed again on every restart.
CrowdStrike withdrew the update in a little over an hour. By then, every online Windows machine running the sensor had received it. The fix required a person to start each affected computer in a recovery mode and delete one file, which CrowdStrike identified as Channel File 291. For an organization with thousands of machines, many of them encrypted with BitLocker and spread across locations, that meant days of hands-on work.
Was the CrowdStrike outage a cyberattack?
No. CrowdStrike and government agencies confirmed that the outage came from a faulty update and not from an attack. Mac and Linux computers were not affected.
Why did one update cause so much damage?
Three reasons.
- Deep access. Security software runs at the core of the operating system so that it can stop malware. An error at that level crashes the whole machine.
- Speed. The update went to all customers at about the same time, with no staged rollout that would have caught the defect on a small group first.
- Concentration. Thousands of large organizations use the same product, so one mistake landed everywhere at once.
Were small businesses affected?
Many were, in two ways. Some run CrowdStrike directly or through their IT provider, and their own computers crashed. Many more felt it second-hand: a canceled flight, a payment terminal that stopped working, a supplier who could not ship, a cloud service that went offline.
That second group holds the broader lesson. You can be knocked out by a failure in a product you have never heard of.
What is business continuity planning?
Business continuity planning is the work of deciding, in advance, how your business keeps operating during a disruption and how it returns to normal. Disaster recovery is the part that restores your technology. Continuity covers the whole operation: people, processes, suppliers, and communication.
The cause can be an outage, a ransomware attack, a fire, a typhoon, or a vendor failure. A good plan does not care which.
How do I write a business continuity plan?
A small business plan can fit in five to ten pages.
- List your critical functions. Taking payments, serving customers, paying staff, ordering stock, answering the phone.
- Set a tolerance for each. How long can it stay down before real damage begins: an hour, a day, a week?
- Map what each function depends on. Systems, vendors, people, and locations.
- Write a manual workaround for each. Paper forms, a card imprinter or a backup payment app, a printed schedule, a phone tree.
- Set recovery priorities. Decide which systems come back first.
- Build the contact list. Staff, vendors, the bank, the insurer, key customers. Include personal phone numbers.
- Assign roles. Name who decides, who talks to customers, and who calls the vendors.
- Store it offline. Print copies. Keep one at home.
- Test it once a year.
How do I prepare for a mass computer outage?
The July outage exposed gaps that are cheap to close.
- Keep your BitLocker recovery keys where you can reach them. Many organizations could not repair their computers because the recovery keys lived on servers that had also crashed. Know where yours are stored, and keep a copy that does not depend on the systems it unlocks.
- Keep an offline list of administrator credentials in a safe or a password manager you can open from a phone.
- Make sure at least two people can perform a recovery. One of them should not be an outside vendor who will be swamped with every other client that day.
- Print the essentials. The day’s appointments, key customer phone numbers, price lists, and emergency procedures.
- Have a second way to take payments and a second way to communicate if email is down.
- Keep a spare laptop that is set up and updated.
- Ask your IT provider how many clients it would have to restore at once, and where you sit in that line.
Should I turn off automatic updates after this?
No. Unpatched software causes far more harm than bad updates do. Most ransomware and data theft exploits flaws for which a fix already existed. One faulty update in a decade does not change that math.
What you can do is stage updates when a product allows it:
- Apply security updates to a few test machines first, then the rest a day or two later.
- Avoid updating every server in the same hour.
- Keep operating system and security definition updates automatic on ordinary workstations.
After the outage, CrowdStrike committed to more testing, staged rollouts, and giving customers more control over when content updates arrive.
What should I ask my software vendors?
- How do you test updates before release?
- Do you roll updates out in stages?
- Can I control when updates install, or delay them?
- How do you notify customers of a problem, and how fast?
- What is your process for withdrawing a bad update?
- What does our contract say about outages?
Ask these of your security vendor, your IT provider’s remote management tool, and any software with deep access to every computer you own.
Does insurance cover an outage like this?
Sometimes. Some cyber policies include “system failure” coverage for outages that are not attacks, and “dependent” or “contingent” business interruption coverage for a vendor’s failure. Many policies exclude one or both, cap them with low limits, or apply a waiting period of 8 to 12 hours before coverage starts. Read your policy or ask your broker. Software license agreements usually limit the vendor’s liability to the fees you paid.
What scams follow a major outage?
Criminals moved within hours. Government agencies warned of phishing emails, fake “fix” files that carried malware, phone calls from people posing as CrowdStrike or Microsoft support, and newly registered look-alike websites. The pattern repeats after every large event.
During any outage, take instructions only from the vendor’s official website and from your own IT provider, reached at a number you already have. Tell your staff the same. Our guide to spotting a phishing email covers the signs.
Is relying on one vendor a mistake?
Not by itself. A small business can’t run two of everything, and a single well-run product is easier to keep secure than a patchwork. The mistake is depending on one vendor with no plan for the day it fails. We made the same point after the Change Healthcare attack. Know your single points of failure, and have a workaround written down for each.
How do I test my plan?
Run a tabletop exercise. Gather the owner, the office manager, and your IT contact for an hour. Pose the scenario: it is 8 a.m. on a Friday, every computer shows a blue screen, and your IT provider’s phone is busy. Walk through the day. How do you open? How do you take payments? Who calls customers? Where is the recovery key? Write down every answer that begins with “I don’t know.” Those are your action items.
Your next step
Find out where your BitLocker recovery keys are stored and whether you could reach them with every company computer down. Then print your contact list. Cerberus Cybersecurity writes business continuity and incident response plans for small businesses and runs the exercises that test them. See our services or contact us.