Explore Legal.io

For Clients
Legal.io company logo
Hire Talent
Find the best fit for any legal role
For Members
Jobs
The best legal jobs, updated daily
Salaries
Benchmark compensation for any legal role
Learn
Learn and grow with our community
Events
Connect with peers at exclusive events
Apps
Tools to streamline legal work
Advertise on Legal.io
Post a job for free
Reach more qualified applicants quickly
Advertise with Us
Reach a targeted audience

For Clients

Hire Talent
Legal.io company logo
Solutions
Find the best fit for any legal role
New Hire
Get highly qualified candidates in days
Popular Roles
Data & Tools
Budget Calculator
Plan and manage your legal budget
Salary Insights
Compensation data for legal roles
Vendor Directory
The ultimate list of legal tech tools

Global Tech Outage Exposes Digital Vulnerabilities in Major Industries

A software update from cybersecurity firm CrowdStrike caused widespread technology outages on July 19, affecting various sectors globally, including air travel, media, and healthcare.

Global Tech Outage Exposes Digital Vulnerabilities in Major Industries

Industries across the globe felt the crippling effects of a technology outage that brought critical services to a standstill. The incident, which unfolded on Friday, July 19, laid bare the risks inherent in our interconnected digital ecosystems.

The disruptions began with a software update from CrowdStrike, a cybersecurity firm that services thousands of clients worldwide. The update, intended to bolster defenses against online threats, inadvertently triggered a cascade of failures in systems running Microsoft Windows. This was not the result of a cyberattack, as confirmed by CrowdStrike, but rather an error that sent the firm scrambling to deploy a remedy.

The ripple effect was immediate and far-reaching. Air travel, media broadcasts, healthcare services, and government functions were among the sectors impacted. Airlines, at the peak of the summer travel season, faced a logistical nightmare as flights were grounded, and passengers were left stranded in snaking queues at airports across the United States, Europe, and Asia.

Media outlets, too, felt the outage's sting. Local TV stations in the U.S. were unable to air their scheduled news segments, turning to improvisation to keep their audiences informed. Across the Atlantic, broadcasters like the U.K.'s Sky News found themselves off-air, resorting to online streams from dimly lit studios.

Healthcare systems were not spared. Hospitals encountered issues with appointment scheduling, leading to the suspension of patient visits and the cancellation of surgeries.

Cybersecurity experts, while acknowledging the scale of the problem, were quick to caution against opportunistic bad actors who might exploit the situation. Gartner analyst Eric Grenier highlighted the need for vigilance against those claiming to offer assistance in the wake of the outage.

Despite the widespread disruption, economic analysts at Capital Economics projected a minimal long-term impact on the global economy. Nonetheless, the event serves as a stark reminder of the fragility of our digital dependencies and the need for robust safeguards in an era where so much hinges on the seamless operation of technology.

As services began to resume and the digital gears started turning once more, the words of CrowdStrike CEO George Kurtz, who expressed deep regret on NBC's "Today Show," resonate with a sobering clarity. The path forward, it seems, must involve a more resilient and diversified technological infrastructure to withstand the inevitable glitches of an increasingly digital world.

A Close Look at Legal Aftermath

Under the terms and conditions of CrowdStrike's Falcon security software, the company's obligation appears to extend no further than a mere refund of fees paid by its clients, despite the massive outage.

Elizabeth Burgin Waller, who leads the Cybersecurity & Data Privacy practice at Woods Rogers, highlighted the stark limitations of CrowdStrike's liability. The company's standard contract terms essentially cap any potential recovery to the amount paid for the software, leaving users with little recourse to claim damages beyond the fees they've already expended.

However, larger entities that rely on CrowdStrike's Falcon software may have negotiated bespoke terms that could potentially expose the cybersecurity firm to greater liability. Details of such agreements remain confidential, and the extent to which they may differ from standard terms is not publicly known.

Amidst the fallout, companies affected by the update failure are looking beyond CrowdStrike for financial redress. Many are expected to turn to cyber insurers to cover the extensive costs incurred, such as IT services to rectify the issue, lost productivity, customer service remediation, and potential legal fees for those needing to report the incident to investors.

Most cyber insurance policies offer coverage for contingent or dependent business interruption, which could apply to third-party cybersecurity dependencies like CrowdStrike's software. Yet, Waller notes that many policies are designed to respond to malicious activities, such as hacking, rather than software glitches, potentially leading to a wave of litigation against insurers.

In the wake of the disruption, CrowdStrike, a publicly traded entity, faces potential shareholder lawsuits, customer claims for damages, and likely scrutiny from the Securities and Exchange Commission (SEC). The company is expected to file an 8-K report shortly, detailing the mishap with the Falcon update.

This incident coincides with a recent federal court ruling in Manhattan that may offer CrowdStrike some reprieve. The ruling in favor of SolarWinds, which faced SEC allegations of inadequate disclosure following a Russian cyber-espionage breach, suggests that companies like CrowdStrike may not be required to provide exhaustive details in their public disclosures.

Nonetheless, the implications of CrowdStrike's limited liability terms and the broader consequences for cyber insurance coverage are set to be closely watched by legal professionals and corporations alike, as they navigate the complexities of cybersecurity in an increasingly interconnected world.

Legal.io Logo
Welcome to Legal.io

Connect with peers, level up skills, and find jobs at the world's best in-house legal departments

More from Legal.io

Legal.io Newsletter - June 25, 2021

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech.

Legal.io Newsletter - June 25, 2021
Legal OperationsTechnologyIn-House Counsel
Legal.io Newsletter - July 8, 2022

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech.

Legal.io Newsletter - July 8, 2022
Legal OperationsTechnologyIn-House Counsel
The Challenge of Finding Purpose In Your Work

A human being is not a houseplant. Yes, both entities need water, nutrition, sunlight, and continuous gaseous exchange, but a human being has a number of additional requirements in order to flourish. One of those is finding a sense of meaning and purpose.  For many of us, our job enables us to fulfill our ‘houseplant’ needs, however it fails to meet our human needs. Let’s think about how you can ensure your work brings you more than some potting mix and a mist spray.

The Challenge of Finding Purpose In Your Work
CareerMental HealthDiversity and Inclusion
U.S. Courts Warn Lawyers of Large-Scale Phishing Scam Targeting E-Filing Notices

The U.S. federal judiciary warns lawyers about phishing emails mimicking court filing notifications, aimed at directing recipients to malicious websites with viruses.

Washington Becomes Second State to Adopt Alternative Pathways to the Bar

The Washington Supreme Court ruled to adopt the NextGen bar exam, starting July 2026. Other states like Colorado and Minnesota join the effort to provide alternative ways to the bar.

Washington Becomes Second State to Adopt Alternative Pathways to the Bar
Career
Chat GPT-4o: New Capabilities for Legal Use Cases

Features like text-to-speech integration can significantly benefit corporate legal departments by streamlining document management and improving accessibility.

Chat GPT-4o: New Capabilities for Legal Use Cases
Technology
Partner Class Sizes Shrink for Second Consecutive Year

New partner class sizes shrunk by an average of 4% among 22 Am Law 100 firms that made announcements by late November. The trend continues the decline that began in 2023 after firms promoted large class sizes in 2022.

Law Firms
Legal.io Logo
Welcome to Legal.io

Connect with peers, level up your skills, and find jobs at the world's best in-house legal departments