What can be learned from Austin-based CrowdStrike's outage? Photo via Getty Images

Airlines, banks, hospitals and other risk-averse organizations around the world chose cybersecurity company CrowdStrike to protect their computer systems from hackers and data breaches.

But all it took was one faulty CrowdStrike software update to cause global disruptions Friday that grounded flights, knocked banks and media outlets offline, and disrupted hospitals, retailers and other services.

“This is a function of the very homogenous technology that goes into the backbone of all of our IT infrastructure,” said Gregory Falco, an assistant professor of engineering at Cornell University. “What really causes this mess is that we rely on very few companies, and everybody uses the same folks, so everyone goes down at the same time.”

The trouble with the update issued by CrowdStrike and affecting computers running Microsoft's Windows operating system was not a hacking incident or cyberattack, according to CrowdStrike, which apologized and said a fix was on the way.

But it wasn't an easy fix. It required “boots on the ground” to remediate, said Gartner analyst Eric Grenier.

“The fix is working, it’s just a very manual process and there’s no magic key to unlock it,” Grenier said. “I think that is probably what companies are struggling with the most here.”

While not everyone is a client of CrowdStrike and its platform known as Falcon, it is one of the leading cybersecurity providers, particularly in transportation, healthcare, banking and other sectors that have a lot at stake in keeping their computer systems working.

“They’re usually risk-averse organizations that don’t want something that’s crazy innovative, but that can work and also cover their butts when something goes wrong. That’s what CrowdStrike is,” Falco said. “And they’re looking around at their colleagues in other sectors and saying, ‘Oh, you know, this company also uses that, so I’m gonna need them, too.’”

Worrying about the fragility of a globally connected technology ecosystem is nothing new. It's what drove fears in the 1990s of a technical glitch that could cause chaos at the turn of the millennium.

“This is basically what we were all worried about with Y2K, except it’s actually happened this time,” wrote Australian cybersecurity consultant Troy Hunt on the social platform X.

Across the world Friday, affected computers were showing the “blue screen of death” — a sign that something went wrong with Microsoft's Windows operating system.

But what's different now is “that these companies are even more entrenched,” Falco said. "We like to think that we have a lot of players available. But at the end of the day, the biggest companies use all the same stuff.”

Founded in 2011 and publicly traded since 2019, CrowdStrike describes itself in its annual report to financial regulators as having “reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.” It emphasizes its use of artificial intelligence in helping to keep pace with adversaries. It reported having 29,000 subscribing customers at the start of the year.

The Austin, Texas-based firm is one of the more visible cybersecurity companies in the world and spends heavily on marketing, including Super Bowl ads. At cybersecurity conferences, it's known for large booths displaying massive action-figure statues representing different state-sponsored hacking groups that CrowdStrike technology promises to defend against.

CrowdStrike CEO George Kurtz is among the most highly compensated in the world, recording more than $230 million in total compensation in the last three years. Kurtz is also a driver for a CrowdStrike-sponsored car racing team.

After his initial statement about the problem was criticized for lack of contrition, Kurtz apologized in a later social media post Friday and on NBC's “Today Show.”

“We understand the gravity of the situation and are deeply sorry for the inconvenience and disruption,” he said on X.

Richard Stiennon, a cybersecurity industry analyst, said this was a historic mistake by CrowdStrike.

“This is easily the worst faux pas, technical faux pas or glitch of any security software provider ever,” said Stiennon, who has tracked the cybersecurity industry for 24 years.

While the problem is an easy technical fix, he said, it’s impact could be long-lasting for some organizations because of the hands-on work needed to fix each affected computer. “It’s really, really difficult to touch millions of machines. And people are on vacation right now, so, you know, the CEO will be coming back from his trip to the Bahamas in a couple of weeks and he won’t be able to use his computers.”

Stiennon said he did not think the outage revealed a bigger problem with the cybersecurity industry or CrowdStrike as a company.

“The markets are going to forgive them, the customers are going to forgive them, and this will blow over,” he said.

Forrester analyst Allie Mellen credited CrowdStrike for clearly telling customers what they need to do to fix the problem. But to restore trust, she said there will need to be a deeper look at what occurred and what changes can be made to prevent it from happening again.

“A lot of this is likely to come down to the testing and software development process and the work that they’ve put into testing these kinds of updates before deployment,” Mellen said. “But until we see the complete retrospective, we won’t know for sure what the failure was.”

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Houston urban agricultural nonprofit gears up for opening of new farm in Second Ward

GROWING FOR GOOD

Small Places, a Houston-based urban agricultural nonprofit, is looking forward to putting down roots beyond the fresh vegetables they grow in the East End.

After securing a 40-year land agreement with Harris County, the organization, which provides produce to families facing food insecurity in the Second Ward, is expecting to open their new farm in February 2025. Small Places’ founders hope the 1.5 acres of land named Finca Tres Robles, located at 5715 Canal Street, will be the beginning of Houston’s urban farming movement.

Founded in 2014 by brothers Daniel, Mark, and Thomas Garcia-Prats, Small Places was born out of the latter brother’s desire to work on an organic farm in his hometown of Houston. After farming in Maine, Iowa, and Nicaragua, Thomas had hoped to manage an urban farm but was unable to find a place. He then roped his brothers, who had no agricultural background at the time, into creating one.

“I joke that my journey in agriculture started the day we started out there. We didn’t grow up gardening or farming or anything of the sort,” says Daniel, Small Places’ director of operations. “It was a big learning curve, but how we approached it to our benefit was through our diverse set of backgrounds.”

Small Places began their need-based produce distribution programs through a partnership with nearby pre-school, Ninfa Lorenzo Early Childhood Center, providing food insecure families with fresh produce and later cooking lessons in 2017. When COVID-19 hit Houston in 2020, Daniel says Small Places pivoted towards becoming a redistribution center for their farming contacts who needed to offload produce as restaurants shut down, selling their crops through the organization. Their neighborhood produce program was then born, providing free boxes of produce to nearly 200 families in the East End at the pandemic’s peak.

“We found ourselves in the middle of two communities who were in need, one being people in our community who were losing jobs and were in need of food as well as our farming connections who were losing restaurant accounts,” Daniel explains.

Small Places grows a variety of vegetables at their East End based farm, selling them at a weekly farm stand. (Photo courtesy Small Places)Small Places grows a variety of vegetables at their East End based farm, selling them at a weekly farm stand. (Photo courtesy Small Places)

Small Places currently assists 65 families living predominantly within two miles of their original location and they recently restarted their programming with Ninfa Lorenzo Early Childhood Center, and accepts Supplemental Nutrition Assistance Program benefits (SNAP) at their farm stand. Daniel says once Finca Tres Robles opens, Small Places plans to bring back cooking classes and educational seminars on healthy eating for which his brother Mark, a former teacher, created the original curriculum. The farm will also have a grocery store stocked with Finca Tres Robles' produce and eventually food staples from local vendors.

“Being social and preparing a meal can be fun, interesting, and delicious. Being able to pull all of that into a program was really important for us,” Daniel explains.

Farming successfully in the middle of Houston for their subsidized programs and produce market requires Small Places’ team to be strategic in their operations. Using his background in engineering and manufacturing, Daniel says they’ve closely monitored trends in which crops perform the best in Houston’s varied, humid climate over the past decade.

They also follow Thomas’s philosophy of allowing nature to work for them, planting crops at times when specific pests are minimal or integrating natural predators into their environment. And lots of composting. Daniel says they accept compostable materials from community members, before burying the raw organic matter in the earth in between their plant beds, allowing it to mature, then later using it to nourish their crops. Daniel says he and his co-founders hope to see more community-focused, sustainable operations like theirs spring up across Houston.

“Small Places is about hopefully more than one farm and really trying to turn urban agriculture and a farm like ours from a novel thing into something that’s just a part of communities and the fabric of Houston for generations to come,” Daniel says.

Houston female-focused health tech accelerator names top companies at annual event

you go girls

A Houston organization that accelerates and supports female founders leading innovative health tech startups has concluded its 2024 program with the announcement of this year's top companies.

Ignite Health, an accelerator founded in 2017 by longtime Houston health care professional Ayse McCracken, named its 2024 winners at its annual Fire Pitch Competition in Houston last month. The companies pitched health tech solutions across lung health, renal therapy, breastfeeding tech, and more.

"This year’s competition was a culmination of passion, innovation, and hard work from the top startups in our 2024 Accelerator Program," reads a LinkedIn post from Ignite. "These trailblazing founders earned their spot on the stage by demonstrating exceptional leadership and the potential to revolutionize the healthcare industry with their solutions and devices."

First place winner was Sarah Lee, CEO and co-founder of Relavo, a New York-based company that's making home dialysis more effective, safer, and more affordable. Lee accepted awards from Johnson & Johnson and Wilson Sonsini Goodrich & Rosati.

Therese Canares, CEO and founder of CurieDx, took second place and won its awards from SWPDC - Southwest National Pediatric Device Innovation Consortium and Wilson Sonsini. CurieDx, based in Baltimore, Maryland, is creating remote diagnostic tools using smartphone technology.

In third place is Andrea Ippolito, CEO and founder of SimpliFed, a company focused on democratizing access to baby feeding and breastfeeding services through virtual care that's covered by insurance. The startup won awards from Texas Children's Hospital and Wilson Sonsini Goodrich & Rosati.

Three other finalists won other awards, including:

  • Kadambari Beelwar, CEO and co-founder, Henderson, Nevada-based Truss Health, which created an AI-powered sensor fusion platform that's designed to detect early signs of infection, won an award presented by Memorial Hermann Health System and Golden Seeds
  • Mimi Gendreau Kigawa, CEO and co-founder of New York-based Zeph Technologies, an AI-lung care company with technology for clinicians to deliver pulmonary care to patients with chronic respiratory disease, won an award presented by CU Innovations and Houston Methodist
  • Ashley Yesayan, CEO and co-founder, New York-based OneVillage, a software platform meant to support patients and family members through trying health events, won an award presented by CU Innovations

The companies were evaluated by the 2024 judges, which included: Allison Rhines, head of JLABS Houston; Andrew Truscott, global health technology lead at Accenture; Angela Shippy, senior physician executive at Amazon Web Services; Kimberly Muller, executive director of CU Innovations at University of Colorado Anschutz Medical Campus; Myra Davis, chief innovation and information officer at Texas Children's Hospital; and Winjie Tang Miao, senior executive vice president and COO of Texas Health Resources.

Houston expert: Balancing flexibility, accountability, and performance in a hybrid world

guest column

Amazon, Salesforce, and Nike are just a few companies making headlines in 2024 for requiring employees to return to the office.

At the same time, technology is evolving, automation and efficiency gains are taking center stage, and employees continue to seek greater flexibility. This has fueled the debate around the future of where work gets done in 2025 and beyond.

Proponents of a remote or hybrid work model believe it leads to increased employee productivity, higher job satisfaction, and access to a larger talent pool. Detractors have a different viewpoint – suggesting employee isolation is greater, cyber security concerns are more complex to manage, and it’s hard to accurately evaluate employee performance.

So, what’s the answer?

The future of work lies in harnessing the power of the employer/employee relationship. This involves establishing clear guidelines for what working “looks like” inside and outside the company, measuring performance tied to company goals, and holding leaders and employees accountable for how these interactions occur.

A remote work policy helps establish clear guidelines. For example, should business cameras be on for all meetings? What is considered an acceptable business casual dress code? Can pets be on screen? Addressing the issues around a remote workspace, how to interact during a meeting, and what to wear helps to define company expectations and how you would like your business to be represented.

Formal performance management tools and processes have been in place for decades. While an annual event is important, encouraging managers and employees to have regular and structured performance conversations and share transparent feedback (regardless of where they work) helps you celebrate what’s exceptionally good, acknowledge what’s on track, and quickly course correct when needed.

Accountability in the remote work environment goes both ways, and leaders must model the behaviors they expect from employees. When the rule is cameras on, that means everyone, regardless of their title. When you’ve established working hours, be available to take the call or respond to the Teams chat within a reasonable timeframe. And when you need to be away from work, set expectations for when and how to reach you.

So, where is the best place to start when updating or establishing guidelines? First, review your key business objectives and work out what’s required to support the successful achievement of those goals. Design your remote and/or hybrid model around those objectives and place employees at the forefront of that design.

If you think about it, it’s no different than being in the office. You expect your employees and managers to show up, be fully present, and hold themselves accountable. That should be the expectation no matter where you “sit.”

------

Michelle Mikesell is the chief people officer at Houston-based G&A Partners.