What can be learned from Austin-based CrowdStrike's outage? Photo via Getty Images

Airlines, banks, hospitals and other risk-averse organizations around the world chose cybersecurity company CrowdStrike to protect their computer systems from hackers and data breaches.

But all it took was one faulty CrowdStrike software update to cause global disruptions Friday that grounded flights, knocked banks and media outlets offline, and disrupted hospitals, retailers and other services.

“This is a function of the very homogenous technology that goes into the backbone of all of our IT infrastructure,” said Gregory Falco, an assistant professor of engineering at Cornell University. “What really causes this mess is that we rely on very few companies, and everybody uses the same folks, so everyone goes down at the same time.”

The trouble with the update issued by CrowdStrike and affecting computers running Microsoft's Windows operating system was not a hacking incident or cyberattack, according to CrowdStrike, which apologized and said a fix was on the way.

But it wasn't an easy fix. It required “boots on the ground” to remediate, said Gartner analyst Eric Grenier.

“The fix is working, it’s just a very manual process and there’s no magic key to unlock it,” Grenier said. “I think that is probably what companies are struggling with the most here.”

While not everyone is a client of CrowdStrike and its platform known as Falcon, it is one of the leading cybersecurity providers, particularly in transportation, healthcare, banking and other sectors that have a lot at stake in keeping their computer systems working.

“They’re usually risk-averse organizations that don’t want something that’s crazy innovative, but that can work and also cover their butts when something goes wrong. That’s what CrowdStrike is,” Falco said. “And they’re looking around at their colleagues in other sectors and saying, ‘Oh, you know, this company also uses that, so I’m gonna need them, too.’”

Worrying about the fragility of a globally connected technology ecosystem is nothing new. It's what drove fears in the 1990s of a technical glitch that could cause chaos at the turn of the millennium.

“This is basically what we were all worried about with Y2K, except it’s actually happened this time,” wrote Australian cybersecurity consultant Troy Hunt on the social platform X.

Across the world Friday, affected computers were showing the “blue screen of death” — a sign that something went wrong with Microsoft's Windows operating system.

But what's different now is “that these companies are even more entrenched,” Falco said. "We like to think that we have a lot of players available. But at the end of the day, the biggest companies use all the same stuff.”

Founded in 2011 and publicly traded since 2019, CrowdStrike describes itself in its annual report to financial regulators as having “reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.” It emphasizes its use of artificial intelligence in helping to keep pace with adversaries. It reported having 29,000 subscribing customers at the start of the year.

The Austin, Texas-based firm is one of the more visible cybersecurity companies in the world and spends heavily on marketing, including Super Bowl ads. At cybersecurity conferences, it's known for large booths displaying massive action-figure statues representing different state-sponsored hacking groups that CrowdStrike technology promises to defend against.

CrowdStrike CEO George Kurtz is among the most highly compensated in the world, recording more than $230 million in total compensation in the last three years. Kurtz is also a driver for a CrowdStrike-sponsored car racing team.

After his initial statement about the problem was criticized for lack of contrition, Kurtz apologized in a later social media post Friday and on NBC's “Today Show.”

“We understand the gravity of the situation and are deeply sorry for the inconvenience and disruption,” he said on X.

Richard Stiennon, a cybersecurity industry analyst, said this was a historic mistake by CrowdStrike.

“This is easily the worst faux pas, technical faux pas or glitch of any security software provider ever,” said Stiennon, who has tracked the cybersecurity industry for 24 years.

While the problem is an easy technical fix, he said, it’s impact could be long-lasting for some organizations because of the hands-on work needed to fix each affected computer. “It’s really, really difficult to touch millions of machines. And people are on vacation right now, so, you know, the CEO will be coming back from his trip to the Bahamas in a couple of weeks and he won’t be able to use his computers.”

Stiennon said he did not think the outage revealed a bigger problem with the cybersecurity industry or CrowdStrike as a company.

“The markets are going to forgive them, the customers are going to forgive them, and this will blow over,” he said.

Forrester analyst Allie Mellen credited CrowdStrike for clearly telling customers what they need to do to fix the problem. But to restore trust, she said there will need to be a deeper look at what occurred and what changes can be made to prevent it from happening again.

“A lot of this is likely to come down to the testing and software development process and the work that they’ve put into testing these kinds of updates before deployment,” Mellen said. “But until we see the complete retrospective, we won’t know for sure what the failure was.”

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Houston researchers develop breakthrough device that could bypass spinal injuries

breakthrough research

Scientists at Houston Methodist have announced a significant leap forward for spinal cord injury recovery.

The researchers have developed a device that essentially bypasses spinal injuries, allowing signals from previously “lost” functions to reach the brain, a new study published in Nature Communications shows.

“Most current technologies try to improve whatever function remains after a spinal cord injury,” Dr. Damiano Barone, assistant professor of neurosurgery in the Department of Neurosurgery at Houston Methodist and co-lead on the study, said in a news release. “Our goal is different. Rather than fixing the injury itself, we want to bypass it completely and create an alternative route for signals to travel.”

The study involved a single ultrathin circumferential electrode array made to conform around the spinal cord without penetrating neural tissue, which was implanted into rodent and pig models with spinal injuries. The electrode array was able to interpret motor, sensory and autonomic signals around the injury. Think of it as a set of detours that restore road access to isolated towns after a disaster destroys the highway instead of just rebuilding the highway.

Over the course of three days, the arrays detected signals of intended movement from low-frequency spinal oscillations with more than 94 percent accuracy. This worked across species and was replicated in feasibility studies on human cadavers.

This research could serve as a new foundation for neuroprosthetic implants that could restore connectivity to the 2.5 million people worldwide suffering from spinal injuries that result in loss of ability. Future development could result in everything from restored organ function to mobility, according to Houston Methodist.

George Malliaras, the Prince Professor of Technology in the Department of Engineering at the University of Cambridge, who co-led the study, sees it as a fundamental restructuring of the science of spinal trauma.

“This could represent a paradigm change in how we think about spinal cord injuries,” Malliaras said. “Instead of starting from the idea that what is lost is gone forever, this approach asks whether we can restore function by carrying the signal around the injury.”

Further work involving laboratory models will need to be completed before launching human trials.

Grants from the National Institutes of Health, Houston Methodist Katz Investigator Award, Helaers Research Award and the Engineering and Physical Sciences Research Council helped support the study. Other collaborators on the study include Salim Hadwe, Ruben Serrano, George Psaltakis, Margaux Forner, Chaeyeon Lee, Sydney Swedick, Moleca Ghnnam, Tawfique Hasan and Alejandro Carnicer-Lombarte from the University of Cambridge; and Anton Banta and Xueer Zhang from Houston Methodist.

Abbott assembles expert team to help lure U.S. Space Academy to Texas

space race

State Rep. Greg Bonnen of Friendswood has been tapped to lead a new team that will promote Texas as the future home of the U.S. Space Academy.

Bonnen, a neurosurgeon, chairs Houston Physicians’ Hospital and the powerful Texas House Appropriations Committee. His House district is close to NASA’s Johnson Space Center.

Gov. Greg Abbott appointed the seven-member team. Last month, President Trump signed an executive order establishing the Presidential Commission on the U.S. Space Academy. Commission members, who held their first meeting this month, will recommend a permanent location for the academy.

Texas officials are pushing a site near Johnson Space Center to host the academy. Alabama, Colorado and Florida are among Texas’ competitors.

In a joint statement, U.S. Sen. Ted Cruz and U.S. Rep. Brian Babin, both of Texas, issued a statement backing the state’s bid for the academy. Cruz lives in Houston. Babbin lives in Woodville, about 55 miles south of Beaumont.

“America’s space program is built across the country, but Texas is where the pieces come together,” the lawmakers said. “We are ready to lead the next generation of space pioneers and look forward to showing why Texas is the right home for the U.S. Space Academy.”

The academy’s curriculum will include technical education, leadership development and public service components. Graduates will be set up for careers in the U.S. military, civil service, and aerospace sectors.

The Abbott-appointed team will work with the Texas Space Commission to prepare the state’s proposal for the academy.

In addition to Bonnen, team members with ties to Houston include:

  • Robert Ambrose, who grew up in Houston. He worked at Johnson Space Center before becoming associate director of the Texas A&M Space Institute.
  • Former NASA astronaut Nancy Curry-Gregg, director of the Texas A&M Space Institute. She earned a doctoral degree from the University of Houston and previously worked at Johnson Space Center.
  • Former NASA astronaut Jack Fischer, senior vice president of Houston-based Intuitive Machines. The company builds spacecraft, delivers payloads to the moon and launches satellites.

“Texas is the home of America’s human spaceflight program,” Abbott said in a release. “No state can match what Texas brings to this mission.”

“NASA’s Johnson Space Center, world-class universities, a premier commercial space industry, major military installations, and an unmatched aerospace workforce give Texas every asset the United States Space Academy requires,” the governor added.