Analysis: Determining the Financial Responsibility for the Crowdstrike Outage

Crowdstrike experienced significant difficulties on July 19. During a standard software update, the cybersecurity company released a file that caused a logic error, preventing Windows machines from rebooting. Microsoft estimates that approximately 8.5 million computers were impacted by this incident.

This caused a cascade of issues, as numerous industry operations reliant on these computers faced disruptions in data coordination and processing.

The aviation sector was severely affected, with FlightAware reporting over 10,000 flight cancellations since July 19, with Delta Air Lines particularly impacted. Using conservative estimates, assuming an average of 64 passengers per flight and a ticket cost of $290 (RM1,320), the direct revenue loss amounted to over $180 million (RM819.7 million).

Additionally, the ripple effects on the hospitality industry, including canceled hotel bookings, car rentals, and missed cruises, are likely to be substantially higher.

Other sectors faced similar disruptions. In some regions, 911 services were unreachable, resulting in unanswered emergency calls, potentially leading to fatalities. Numerous large hospital systems also suffered, with nonemergency procedures and appointments being postponed or canceled.

The severity of this disruption did not go unnoticed. The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection has called for a meeting with Crowdstrike CEO George Kurtz.

The pressing question now is: Who will bear the costs of these delays, cancellations, and consequences?

Investors on Wall Street were the first to feel the impact, with Crowdstrike’s market capitalization dropping by over $10 billion (RM45.5 billion) by July 22. How long it will take for Crowdstrike’s stock to recover remains uncertain.

Ironically, Crowdstrike’s software is designed to safeguard computers from viruses and malicious software. Yet, the current outages caused damage comparable to a cyberattack. Using a military analogy, the situation is akin to friendly fire.

Fortunately, the problematic file was swiftly fixed in under 80 minutes. However, the damage to the 8.5 million affected computers had already been done, with some requiring manual intervention to resolve the issue.

Does this make Crowdstrike liable for the necessary repairs and the resulting damages?

Every software product includes terms and conditions limiting the owner’s liability for malfunctions or disruptions. Users typically agree to these terms without reading them, thus holding the software owner harmless.

Despite this, the outage is likely to result in a slew of class-action lawsuits, with attorneys seeking damages on behalf of the affected parties, likely leading to out-of-court settlements.

More importantly, the Crowdstrike outage highlights the vulnerability of all organizations reliant on computers to a single bad file or inadvertent error. This incident could have happened to any cybersecurity company, albeit perhaps on a smaller scale. Such risks are inherent in our reliance on digital efficiency and the digital economy.

No one desires a return to manual, paper-based processes when digital solutions are far more efficient and accurate.

This incident also offers a glimpse into the future, where AI system glitches could cause even more extensive cyber meltdowns, disrupting financial, transportation, and healthcare systems beyond human-caused failures.

While Crowdstrike may bear some responsibility for the July 19 incident, the demand for digital efficiency is equally culpable. The congressional committee questioning Crowdstrike’s CEO may struggle to fully grasp this reality.

The coming months will be crucial as liability issues are examined and discussed. However, the alternative to cybersecurity protection, which is no protection at all, poses a far greater danger than what occurred on July 19.

This is the reality of our digital economy, which brings numerous benefits and conveniences but also inherent risks, both apparent and hidden, as illustrated by the events of July 19. – Chicago Tribune/Tribune News Service

More Articles & Posts