What can be learned from Austin-based CrowdStrike's outage? Photo via Getty Images

Airlines, banks, hospitals and other risk-averse organizations around the world chose cybersecurity company CrowdStrike to protect their computer systems from hackers and data breaches.

But all it took was one faulty CrowdStrike software update to cause global disruptions Friday that grounded flights, knocked banks and media outlets offline, and disrupted hospitals, retailers and other services.

“This is a function of the very homogenous technology that goes into the backbone of all of our IT infrastructure,” said Gregory Falco, an assistant professor of engineering at Cornell University. “What really causes this mess is that we rely on very few companies, and everybody uses the same folks, so everyone goes down at the same time.”

The trouble with the update issued by CrowdStrike and affecting computers running Microsoft's Windows operating system was not a hacking incident or cyberattack, according to CrowdStrike, which apologized and said a fix was on the way.

But it wasn't an easy fix. It required “boots on the ground” to remediate, said Gartner analyst Eric Grenier.

“The fix is working, it’s just a very manual process and there’s no magic key to unlock it,” Grenier said. “I think that is probably what companies are struggling with the most here.”

While not everyone is a client of CrowdStrike and its platform known as Falcon, it is one of the leading cybersecurity providers, particularly in transportation, healthcare, banking and other sectors that have a lot at stake in keeping their computer systems working.

“They’re usually risk-averse organizations that don’t want something that’s crazy innovative, but that can work and also cover their butts when something goes wrong. That’s what CrowdStrike is,” Falco said. “And they’re looking around at their colleagues in other sectors and saying, ‘Oh, you know, this company also uses that, so I’m gonna need them, too.’”

Worrying about the fragility of a globally connected technology ecosystem is nothing new. It's what drove fears in the 1990s of a technical glitch that could cause chaos at the turn of the millennium.

“This is basically what we were all worried about with Y2K, except it’s actually happened this time,” wrote Australian cybersecurity consultant Troy Hunt on the social platform X.

Across the world Friday, affected computers were showing the “blue screen of death” — a sign that something went wrong with Microsoft's Windows operating system.

But what's different now is “that these companies are even more entrenched,” Falco said. "We like to think that we have a lot of players available. But at the end of the day, the biggest companies use all the same stuff.”

Founded in 2011 and publicly traded since 2019, CrowdStrike describes itself in its annual report to financial regulators as having “reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.” It emphasizes its use of artificial intelligence in helping to keep pace with adversaries. It reported having 29,000 subscribing customers at the start of the year.

The Austin, Texas-based firm is one of the more visible cybersecurity companies in the world and spends heavily on marketing, including Super Bowl ads. At cybersecurity conferences, it's known for large booths displaying massive action-figure statues representing different state-sponsored hacking groups that CrowdStrike technology promises to defend against.

CrowdStrike CEO George Kurtz is among the most highly compensated in the world, recording more than $230 million in total compensation in the last three years. Kurtz is also a driver for a CrowdStrike-sponsored car racing team.

After his initial statement about the problem was criticized for lack of contrition, Kurtz apologized in a later social media post Friday and on NBC's “Today Show.”

“We understand the gravity of the situation and are deeply sorry for the inconvenience and disruption,” he said on X.

Richard Stiennon, a cybersecurity industry analyst, said this was a historic mistake by CrowdStrike.

“This is easily the worst faux pas, technical faux pas or glitch of any security software provider ever,” said Stiennon, who has tracked the cybersecurity industry for 24 years.

While the problem is an easy technical fix, he said, it’s impact could be long-lasting for some organizations because of the hands-on work needed to fix each affected computer. “It’s really, really difficult to touch millions of machines. And people are on vacation right now, so, you know, the CEO will be coming back from his trip to the Bahamas in a couple of weeks and he won’t be able to use his computers.”

Stiennon said he did not think the outage revealed a bigger problem with the cybersecurity industry or CrowdStrike as a company.

“The markets are going to forgive them, the customers are going to forgive them, and this will blow over,” he said.

Forrester analyst Allie Mellen credited CrowdStrike for clearly telling customers what they need to do to fix the problem. But to restore trust, she said there will need to be a deeper look at what occurred and what changes can be made to prevent it from happening again.

“A lot of this is likely to come down to the testing and software development process and the work that they’ve put into testing these kinds of updates before deployment,” Mellen said. “But until we see the complete retrospective, we won’t know for sure what the failure was.”

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

World's largest student startup competition names teams for 2025 Houston event

ready, set, pitch

The Rice Alliance for Technology and Entrepreneurship has announced the 42 student-led teams worldwide that will compete in the 25th annual Rice Business Plan Competition this spring.

The highly competitive event, known as one of the world’s largest and richest intercollegiate student startup challenges, will take place April 10–12 at Houston's The Ion. Teams in this year's competition represent 34 universities from four countries, including one team from Rice.

Graduate student-led teams from colleges or universities around the world will present their plans before more than 300 angel, venture capital, and corporate investors to compete for more than $1 million in prizes. Last year, top teams were awarded $1.5 million in investment and cash prizes.

The 2025 invitees include:

  • 3rd-i, University of Miami
  • AG3 Labs, Michigan State University
  • Arcticedge Technologies, University of Waterloo
  • Ark Health, University of Chicago
  • Automatic AI, University of Mississippi and University of New Orleans
  • Bobica Bars, Rowan University
  • Carbon Salary, Washington University in St. Louis
  • Carmine Minerals, California State University, San Bernardino
  • Celal-Mex, Monterrey Institute of Technology and Higher Education
  • CELLECT Laboratories, University of Waterloo
  • ECHO Solutions, University of Houston
  • EDUrain, University of Missouri-St. Louis
  • Eutrobac, University of California, Santa Cruz
  • FarmSmart.ai, Louisiana State University
  • Fetal Therapy Technologies, Johns Hopkins University
  • GreenLIB Materials, University of Ottawa
  • Humimic Biosystems, University of Arkansas
  • HydroHaul, Harvard University
  • Intero Biosystems, University of Michigan
  • Interplay, University of Missouri-Kansas City
  • MabLab, Harvard University
  • Microvitality, Tufts University
  • Mito Robotics, Carnegie Mellon University
  • Motmot, Michigan State University
  • Mud Rat, University of Connecticut
  • Nanoborne, University of Texas at Austin
  • NerView Surgical, McMaster University
  • NeuroFore, Washington University in St. Louis
  • Novus, Stanford University
  • OAQ, University of Toronto
  • Parthian Baattery Solutions, Columbia University
  • Pattern Materials, Rice University
  • Photon Queue, University of Illinois, Urbana-Champaign
  • re.solution, RWTH Aachen University
  • Rise Media, Yale University
  • Rivulet, University of Cambridge and Dartmouth College
  • Sabana, Carnegie Mellon University
  • SearchOwl, Case Western Reserve University
  • Six Carbons, Indiana University
  • Songscription, Stanford University
  • Watermarked.ai, University of Illinois, Urbana-Champaign
  • Xatoms, University of Toronto

This year's group joins more than 868 RBPC alums that have raised more than $6.1 billion in capital with 59 successful exits, according to the Rice Alliance.

Last year, Harvard's MesaQuantum, which was developing accurate and precise chip-scale clocks, took home the biggest sum of $335,000. While not named as a finalist, the team secured the most funding across a few prizes.

Protein Pints, a high-protein, low-sugar ice cream product from Michigan State University, won first place and the $150,000 GOOSE Capital Investment Grand Prize, as well as other prizes, bringing its total to $251,000.

Tesla recalling more than 375,000 vehicles due to power steering issue

Tesla Talk

Tesla is recalling more than 375,000 vehicles due to a power steering issue.

The recall is for certain 2023 Model 3 and Model Y vehicles operating software prior to 2023.38.4, according to the National Highway Traffic Safety Administration.

The printed circuit board for the electronic power steering assist may become overstressed, causing a loss of power steering assist when the vehicle reaches a stop and then accelerates again, the agency said.

The loss of power could required more effort to control the car by drivers, particularly at low speeds, increasing the risk of a crash.

Tesla isn't aware of any crashes, injuries, or deaths related to the condition.

The electric vehicle maker headed by Elon Musk has released a free software update to address the issue.

Letters are expected to be sent to vehicle owners on March 25. Owners may contact Tesla customer service at 1-877-798-3752 or the NHTSA at 1-888-327-4236.

Houston space tech companies land $25 million from Texas commission

Out Of This World

Two Houston aerospace companies have collectively received $25 million in grants from the Texas Space Commission.

Starlab Space picked up a $15 million grant, and Intuitive Machines gained a $10 million grant, according to a Space Commission news release.

Starlab Space says the money will help it develop the Systems Integration Lab in Webster, which will feature two components — the main lab and a software verification facility. The integration lab will aid creation of Starlab’s commercial space station.

“To ensure the success of our future space missions, we are starting with state-of-the-art testing facilities that will include the closest approximation to the flight environment as possible and allow us to verify requirements and validate the design of the Starlab space station,” Starlab CEO Tim Kopra said in a news release.

Starlab’s grant comes on top of a $217.5 million award from NASA to help eventually transition activity from the soon-to-be-retired International Space Station to new commercial destinations.

Intuitive Machines is a space exploration, infrastructure and services company. Among its projects are a lunar lander designed to land on the moon and a lunar rover designed for astronauts to travel on the moon’s surface.

The grants come from the Space Commission’s Space Exploration and Aeronautics Research Fund, which recently awarded $47.7 million to Texas companies.

Other recipients were:

  • Cedar Park-based Firefly Aerospace, which received $8.2 million
  • Brownsville-based Space Exploration Technologies (SpaceX), which received $7.5 million
  • Van Horn-based Blue Origin, which received $7 million

Gwen Griffin, chair of the commission, says the grants “will support Texas companies as we grow commercial, military, and civil aerospace activity across the state.”

State lawmakers established the commission in 2023, along with the Texas Aerospace Research & Space Economy Consortium, to bolster the state’s space industry.