Expert reaction to Crowdstrike IT disaster
Academic experts from City and Bayes have shared their reactions to the IT update from Crowdstrike that affected IT systems globally. Cybersecurity firm Crowdstrike ran an update that affected Windows operating systems, affecting IT systems in healthcare, airlines, small retailers, payroll, and more. The root cause for the issue has been identified as a driver update relating to Crowdstrike’s Falcon Sensor security software. In what Tesla and X CEO Elon Musk has described as the ‘biggest IT fail ever’, from Brisbane to Luton, over 3300 flights around the world have been cancelled, GP surgeries have been postponed, UK broadcasters like Sky News and some BBC programmes were unable to produce programmes for television, and people were unable to pay for things like coffee and taxis by electronic card, having to resort to cash. Crowdstrike boss George Kurtz has confirmed it was not a cyberattack, but has acknowledged that it could be some time before things are resolved. Microsoft has recommendations on its website for users encountering issues, with suggestions of rebooting up to 15 times in some cases. Experts from City and Bayes have shared their thoughts on the story as it developed. Muttukrishnan Rajarajan, Professor of Security Engineering and Director of the Institute for Cyber Security at City, University of London, explained:
"The issue is due to a software upgrade from Crowdstrike. Not a well-known name in the security industry. However, has grown quite aggressively and have more than 24,000 customers now. "This is the challenge of digital transformation and far too much dependency on 3rd party vendors for business-critical applications. As the cyber threats are evolving at a rapid phase these companies are also under lot of pressure to upgrade their systems. However, they have limited resources to scale at the level they need to manage such upgrades carefully as there are lot of interdependencies in the supply chain and this is a classic example of the cascading impact a simple upgrade can cause to multiple business sectors and in this case some critical infrastructure providers. "Hopefully the new Cyber Security and Resilience bill proposed this week during the King's speech will enforce more controls in place to improve the infrastructure resilience and avoid such future issues at a larger scale to the critical IT infrastructures of major industries. Airlines will need more efficient solutions One of the more eye-opening aspects of the situation as it affected airlines was the quick shift from IT systems to check in passengers for flights to taking down their names and information manually, via pen and paper. Dr Amit Rawal, Lecturer in Management (Education) added: “The IT outages reflect the issues with a cybersecurity update on complex networks. The aviation and transport industries in particular are impacted due to their reliance on outdated software. Subsequently, their systems have not been able to display flight and train information as well as check people in on flights as per the usual processes. Further implications of this IT outage are expected given the various networks that rely on an update from Crowdstrike.” “Over the course of the next few days, this will cause a number of delays and further cancelations on flights as they will not all be able to fly at their scheduled times. Airlines are likely to have several customers seeking compensation so will have to find more efficient solutions than manual approaches”. Robust operating systems needed Professor Feng Li, Associate Dean of Research and Innovation explained the wider issues surrounding technology and why it’s so surprising this happened..jpg)
No comments:
Post a Comment