Explore Legal.io

For Clients
Legal.io company logo
Hire Talent
Find the best fit for any legal role
For Members
Jobs
The best legal jobs, updated daily
Salaries
Benchmark compensation for any legal role
Learn
Learn and grow with our community
Events
Connect with peers at exclusive events
Apps
Tools to streamline legal work
Advertise on Legal.io
Post a job for free
Reach more qualified applicants quickly
Advertise with Us
Reach a targeted audience

For Clients

Hire Talent
Legal.io company logo
Solutions
Find the best fit for any legal role
New Hire
Get highly qualified candidates in days
Popular Roles
Data & Tools
Budget Calculator
Plan and manage your legal budget
Salary Insights
Compensation data for legal roles
Vendor Directory
The ultimate list of legal tech tools

CrowdStrike's IT Outage Sparks Congressional Scrutiny

The outage caused by CrowdStrike's faulty update has prompted Congress to scrutinize the cybersecurity firm's dominance and its implications for national security.

CrowdStrike's IT Outage Sparks Congressional Scrutiny

In the wake of a colossal IT outage that disrupted various sectors across the United States, including courts of justice and numerous law firms, Congress has called upon George Kurtz, CEO of cybersecurity firm CrowdStrike, to testify. The incident has raised significant concerns about the reliance on a single company for critical cybersecurity services and the implications of such dependence on national security and business continuity.

The Massive Outage and Its Impact

On July 19, a global IT outage attributed to a critical failure in CrowdStrike's systems as a result of a faulty update, caused widespread disruptions in companies using Microsoft's Windows operating system. The company, renowned for its endpoint protection and threat intelligence services, faced a catastrophic failure that left numerous industries, including airlines, banking and healthcare, affected. Microsoft released a statement on Saturday saying about 8.5 million Windows devices were affected.

Multiple state court systems, heavily reliant on CrowdStrike's cybersecurity infrastructure, also experienced severe disruptions. Court proceedings were delayed, case management systems went offline, and access to essential legal documents was hindered.

Law firms, which depend on robust cybersecurity to protect sensitive client information and ensure operational integrity, were also severely affected. Many had to activate contingency plans to continue their operations.

Congress’s Concerns and Inquiry

The pervasive impact of the outage has prompted Congressional leaders to scrutinize CrowdStrike's role and its dominance in the cybersecurity market. In a letter published on Monday, July 22, the House Committee on Homeland Security demanded more transparency from Kurtz and invited him to a hearing on the matter. 

"In less than one day, we have seen major impacts to key functions of the global economy, including aviation, healthcare, banking, media, and emergency services," their letter said. "Recognizing that Americans will undoubtedly feel the lasting, real-world consequences of this incident, they deserve to know in detail how this incident happened and the mitigation steps CrowdStrike is taking."

Key Concerns:

  • Dependence on a Single Provider: The outage has illuminated the risks associated with having a single company provide vital cybersecurity services to numerous businesses and government entities. The incident demonstrated how a failure in one company's infrastructure could cascade into a national crisis.

  • National Security Implications: With CrowdStrike's services being integral to protecting sensitive information across various sectors, any vulnerability or failure within the company's systems poses significant national security risks. Congress is likely to explore whether it is prudent to diversify cybersecurity providers to mitigate such risks.

Kurtz is expected to address the root causes of the outage, the steps taken to resolve it, and the measures being implemented to prevent future occurrences. Lawmakers will also probe into CrowdStrike's contingency planning and risk management strategies.

The Dangers of Reliance on a Single Cybersecurity Provider

CrowdStrike is the second largest American cybersecurity company, used by more than half of Fortune 500 companies, New York Times reported. The outage therefore has raised legitimate concerns about the risks of centralizing critical services within one company. 

Federal Trade Commission Chair Lina Khan voiced concern about the situation, underlining that the global outage shows how weak systems that depend on one major supplier are. "All too often these days, a single glitch results in a system-wide outage, affecting industries from healthcare and airlines to banks and auto-dealers," Khan wrote on X. "Millions of people and businesses pay the price. These incidents reveal how concentration can create fragile systems."

Microsoft security executive David Weston partially shares this view, but believes the solution is for tech companies to be more vigilant when deploying updates, not for lawmakers to intervene. "It’s also a reminder of how important it is for all of us across the tech ecosystem to prioritize operating with safe deployment and disaster recovery using the mechanisms that exist," Weston wrote in a blog post.

Future Directions and Recommendations

In light of the recent outage and the upcoming hearing, several recommendations are emerging to strengthen the cybersecurity framework and reduce the risks associated with provider concentration. These include diversification of cybersecurity providers, enhanced regulatory oversight and investment in cyber resilience.

As  Kurtz prepares to testify before the House Committee on Homeland Security, the incident serves as a pivotal moment for the legal and business communities to reassess their cybersecurity strategies. The lessons learned from this outage will likely shape future policies and practices aimed at safeguarding the integrity and continuity of essential services across the country.

Legal.io Logo
Welcome to Legal.io

Connect with peers, level up skills, and find jobs at the world's best in-house legal departments

More from Legal.io

Thomson Reuters to Sell Majority Stake in Elite to TPG to Accelerate Growth of Legal Tech Solutions

Thomson Reuters is selling a majority stake in its legal financial and practice management solutions suite, Elite, to global asset management firm TPG. The deal, valued at $500 million, will enable Elite to operate as a standalone business with a greater focus on accelerating growth and improving law firm finance and accounting operations.

Thomson Reuters to Sell Majority Stake in Elite to TPG to Accelerate Growth of Legal Tech Solutions
Technology
5 Ways To Avoid And Resolve Partnership Disputes

Going into business with a partner can be a great way to work. Two heads are often better than one.

5 Ways To Avoid And Resolve Partnership Disputes
Law FirmsCareerBusiness and Corporate
California Bar Remains Committed to Overhauling the State Exam

Preparations for the exam were put on hold following NCBE allegations of intellectual property infringement.

California Bar Remains Committed to Overhauling the State Exam
Education
Legal.io Newsletter - February 11, 2022

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech.

Legal.io Newsletter - February 11, 2022
Legal OperationsTechnologyIn-House Counsel
3 Millennial Standards for the Legal World

A large portion of today’s workforce consists of millennials (those born between 1980-2000). This generation has defined a modified set of employer standards as they are differently-motivated in the workplace. So how do you keep your millennial legal team engaged? Start with understanding what they are looking for in a firm:

3 Millennial Standards for the Legal World
CareerMental HealthDiversity and Inclusion
50 interview questions for a legal job you should be prepared to answer

You can nail that legal interview with a little bit of preparation!

50 interview questions for a legal job you should be prepared to answer
Career
Mental Health In-House: Navigating Professional Demands and Personal Well-Being

In-house lawyers face significant mental health challenges due to overwhelming workloads, understaffing, and a dysfunctional corporate culture, leading to high levels of stress, anxiety, and burnout.

Mental Health In-House: Navigating Professional Demands and Personal Well-Being
CareerMental Health
The Top Things to Remember When You’re Starting a New Job

Hands have been shaken on your job offer (most likely by email) and arrangements have been set. Now it’s time for the job to begin. Perhaps you feel yourself transported back to the first day of elementary school as you put on your smartest work clothes and head off into the unknown. But whatever you’re feeling, there are a number of things you can do to set yourself up for success during your first few weeks at your new firm. Let’s consider this key initial period.

The Top Things to Remember When You’re Starting a New Job
Law FirmsCareer
Legal.io Logo
Welcome to Legal.io

Connect with peers, level up your skills, and find jobs at the world's best in-house legal departments