This public postmortem from a cybersecurity company with this much responsibility on 2024 is shameful:
Crowdstrike’s focus on attack coverage and detection latency instead of higher level but harder to measure metrics like availability and intrusions, shows the problem of optimizing for the wrong metrics.
CIOs of airlines, hospitals, etc should have been more paranoid about worst-case scenarios, and governments should also have been more proactive about protecting society.
Crowdstrike’s stock down ~33% because of the incident. I thought it would take the company out of business, but there might be too much inertia.
Crowdstrike is giving $10 apology gift cards to their clients when the estimates losses to Fortune 500 companies are ~$5.4B
8.5M computers affected, according to Microsoft, about ~1% of all Windows installs.
Crowdstrike depends on Windows for much of their revenue, but their website’s marketing is not friendly to Windows. I wonder what atmosphere do they have inside the company.
The US government has already started taking steps in the right direction.