Skip to content

CRWD fuck up, how to prevent it

We all know what happened last Friday (19.07.2023). “Crowdstrikers” had a terrible day. What are my thoughts about that situation?

Of course, it is obvious that some team at CRWD missed something, and the testing phase wasn’t good enough. Mistakes happen, and this one had a really big impact. I don’t want to blame the vendor anymore, but what can be done to mitigate such possibilities in the future?

I see a lot of security experts (rather theoretical) who say that organizations don’t test software before deploying it into production. As a system integrator working for quite large companies, before deployment of a new software version of anything, the testing phase or deployment to a small group of people is mandatory. CRWD’s mistake was not delivered through a software update itself but through a content update, which includes information about threats, correlation rules, etc. Who tests threat updates before deploying them to endpoints? Honestly, I don’t know any companies that do this. On the other hand, it will increase the time to deliver information about new threats, thereby decreasing the security posture as well.

So, how do we deal with it? If you have a flexible solution, there is probably an option to delay content updates, for example, like in Cortex XDR.

I’m not a CRWD expert; actually, I don’t know it at all, but it would be strange if such a popular XDR doesn’t have similar capabilities.

Same situation exists with PANW firewalls, where you can delay threat updates as well.

Using a comparable approach, we can maintain both protection at near-normal levels and reduce the risk of scenarios like what happened with CRWD.

Join the conversation

Your email address will not be published. Required fields are marked *